# mcp-audit

> Use this tool when you need to identify security vulnerabilities in Model Context Protocol (MCP) servers, such as prompt injection, over-broad permissions, and credential leaks. It scans MCP servers to detect weaknesses, including weak input validation, and provides outputs to help remediate these issues. Ideal for use in development and security auditing contexts, it takes MCP server configurations as input and returns a report of potential security threats.

Canonical page: https://skillsregistry.net/skills/buildwithabid-mcp-audit  
JSON: https://api.skillsregistry.net/v1/skills/buildwithabid-mcp-audit

## Description

Python security scanner for Model Context Protocol (MCP) servers — find prompt injection, over-broad permissions, weak input validation, and credential leaks before your AI agent does.

## Trust

- **Trust score (0–1):** 0.78
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Category:** ai-ml
- **Updated:** 2026-09-19

## Source

- **Source listing:** [GitHub](https://github.com/BuildWithAbid/mcp-audit)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "buildwithabid-mcp-audit"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/buildwithabid-mcp-audit` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/buildwithabid-mcp-audit/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
