# mcp-audit-tool

> mcp-audit-tool — graygnatconsole-mcp-audit-tool. Use this tool when you need to scan AI agent configurations for potential security risks, such as tool poisoning or hardcoded secrets, and generate SARIF-compatible reports for CI integration. It solves problems related to supply-chain risks, command injection, and rug pulls in Model Context Protocol (MCP) servers. The tool takes AI agent configs as input and outputs security audit reports, making it ideal for use in CI pipelines and security audits.

Canonical page: https://skillsregistry.net/skills/graygnatconsole-mcp-audit-tool  
JSON: https://api.skillsregistry.net/v1/skills/graygnatconsole-mcp-audit-tool

## Description

🛡️ Security audit CLI for Model Context Protocol (MCP) servers — scan AI agent configs for tool poisoning, rug pulls, hardcoded secrets, command injection & supply-chain risks. Pure Python, SARIF + CI ready.

## Trust

- **Trust score (0–1):** 0.83
- **Verification tier:** scanned
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **License:** MIT
- **Updated:** 2026-09-28

## Source

- **Source listing:** [GitHub](https://github.com/graygnatconsole/mcp-audit-tool)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "graygnatconsole-mcp-audit-tool"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/graygnatconsole-mcp-audit-tool` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/graygnatconsole-mcp-audit-tool/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
