Agent Audit MCP Server

Security scanner for AI agent tooling — MCP servers, tool definitions, and agentic pipelines

Local serverstdioPython

What is the Agent Audit MCP server?

Agent Audit MCP server exists for a simple reason — assistants are far more useful when they can act on Agent Audit directly instead of describing what you should do. Security scanner for AI agent tooling — MCP servers, tool definitions, and agentic pipelines.

What you get

Catch prompt injection, command injection, hardcoded secrets, and excessive permissions in your MCP server configurations — before attackers do.

  • 30+ CVEs filed Jan–Feb 2026 — , 43% were command injection
  • Tool poisoning attacks — hide instructions in tool descriptions that hijack LLM behavior
  • Hardcoded secrets — in MCP configs are stored in plaintext at ~/.config/claude/
  • 5 connected MCP servers → 78% attack success rate — (Palo Alto Research, 2026)
  • More capable models are more vulnerable — o1-mini shows 72.8% attack success against poisoned tools (MCPTox benchmark)

Setting it up

agent-audit on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.

Configuration and credentials

You will need 2 environment variables: AWS_ACCESS_KEY_ID, YOUR_API_KEY. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

Choosing this one

Plenty of AI and media services servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. It is maintained by piiiico; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Before you rely on it

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the agent audit mcp server does with a few real requests.

How to install the Agent Audit MCP server

{
  "mcpServers": {
    "agent-audit": {
      "command": "npx",
      "args": ["-y", "agent-audit"],
      "env": {
        "AWS_ACCESS_KEY_ID": "your-value",
        "YOUR_API_KEY": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

VariableDescriptionRequired
AWS_ACCESS_KEY_IDCredential the server authenticates with.Yes
YOUR_API_KEYCredential the server authenticates with.Yes

Frequently asked questions

It connects Agent Audit to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Agent Audit directly.