AUTOMATED MCP SECURITY AUDIT

Audit Your MCP Server in Seconds.

Instant static verification for Model Context Protocol servers. Detect command injection, path traversal, hardcoded tokens, and tool contract drift before agents touch your code.

Initial Turnkey Hardened Configs: ๐Ÿ“ Filesystem MCP Hardened Launch Config ๐Ÿ’ป Shell/Terminal MCP Hardened Launch Config
Connecting to repository...

Target Repository

Analyzed at --

--
--
-- issues found

Free Findings Preview (Top Issues)

Automated Hardening for Your Repository

Don't manually patch path boundaries, shell escapes, and environment leaks. Generate your repository-specific security diff, runtime policy, and regression tests with one click.

100% Free Intent Check ยท Zero Wallet Needed ยท Preview Exact Generated Files

โœ” Payment Settled & Remediation Delivered!

1. Unified Git Patch (src/security-guard.ts)


        
        
      

Verified Security Benchmarks from Public MCP Repositories

MCP Filesystem Server

Verified against symlink path traversal. The remediation patch implements canonical root directory jailing via safeResolvePath(), preventing arbitrary reads of sensitive host files like /etc/passwd.

Shell & Terminal MCP Servers

Audited for arbitrary command execution. Replaces unescaped shell concatenation with argument vector array enforcement and an explicit binary whitelist (git, npm, node).

Web Search & Scraper MCP Servers

Audited for prompt injection surfaces. Employs content delimiter encapsulation and secret token masking to eliminate indirect prompt poisoning from third-party websites.