Show HN: Mcpaudit – static security scanner for MCP servers
Mcpaudit is a static security scanner designed for MCP servers, which allows users to check AI agent plugins for potential security risks. It analyzes the source code and settings of plugins without executing them, identifying dangerous patterns and providing concrete fixes. This tool aims to enhance security by enabling users to perform quick, offline checks before integrating third-party plugins into their AI systems.
- ▪Mcpaudit scans MCP server code for security vulnerabilities before they are used by AI agents.
- ▪The tool operates offline and requires no installation, setup, or internet connection.
- ▪It flags risky patterns in the code and provides recommendations for remediation.
2 outlets in our directory ran this story, first to last over 1 hour. All of the coverage we found sits in one bucket: centre. That one-sidedness is itself worth noticing.
- ▪ Your MCP Server Is Probably Overprivileged - Here's a Scanner For It — DEV.to (Top)
Hacker News (Newest) files mainly under programming. We currently carry 5,306 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | GitHub |
| Canonical URL | https://github.com/allenwu-blip/mcpaudit |
| Publication time | Fri, 22 May 2026 19:52:46 +0000 |
| Retrieval time | 2026-05-22T20:02:02.959Z |
| Last seen | 2026-05-22T20:02:02.959Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | RflUDOvTQfuk · 2 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
mcpaudit A quick security X-ray for AI agent plugins, to run before you plug one in. An MCP server (MCP = Model Context Protocol, the standard way to give an AI assistant new tools) is code you download and let an AI agent run. mcpaudit reads that code before you trust it and points out the dangerous bits — the quick safety check that doesn't really exist for these plugins yet. npx allenwu-blip/mcpaudit ./path-to-an-mcp-server No install, no setup, no API key, no internet needed. It reads the plugin's source code and its settings file and flags risky patterns, ranked by how bad they are, each with a concrete fix. It never runs the code it is checking — it only reads it.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.