make-audit-mcp
Audits Make.com scenario blueprints for security issues, module references, and settings before import.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@make-audit-mcpAudit C:\Downloads\lead-intake.blueprint.json before I import it."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
make-audit-mcp
An MCP server that audits Make.com (Integromat) scenario blueprints before you import them. Blueprints are shared everywhere — template galleries, forums, "1000 automation" bundles — and importing one means importing its webhooks, HTTP calls, and whatever credential-shaped strings the author left inside.
"What's in this blueprint?" — modules, apps, trigger, routers, error handling, scenario settings
"Is it safe to import?" — hardcoded tokens (masked in output), plain-
http://calls, dangling module references, unfiltered router routes, missing error handling, log-retention settings"What feeds module 5?" — mapping-reference tracing in both directions
Make's official MCP runs your scenarios; this one reviews the files before they become scenarios. Local files only.
Quick start
Claude Code
claude mcp add make-audit -- npx -y make-audit-mcpClaude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"make-audit": {
"command": "npx",
"args": ["-y", "make-audit-mcp"]
}
}
}Then: "Audit C:\Downloads\lead-intake.blueprint.json before I import it."
Related MCP server: mcp-heimdall
Tools
Tool | What it does |
| Scenario overview: modules, apps, trigger, routers, error handlers, settings |
| One module in detail — parameters/mappings (secrets masked), references out and in |
| Findings report: errors / warnings / info |
What the auditor checks
Credential-shaped literals in parameters or mappings (
api_key,token,Authorization,Bearer …) — connections are stripped on export, so any literal secret is exactly what shouldn't be in a shared file. Values are masked (supe… (18 chars)) everywhere, including in findings — the auditor never amplifies a leaked token into the model's context.Dangling references — mappings like
{{99.output}}pointing at modules that don't exist (common after hand-editing or merging blueprints). The extractor understands Make's expression syntax:{{formatDate(2.date; "X")}}references module 2, while{{parseNumber(3.14)}}references nothing.Plain-
http://URLs, webhook triggers (anyone with the URL can invoke), routers where no route is filtered, disabled-but-present modules, no error handlers with DLQ off,confidential=falselog retention.
Known limitation: execution-order validation across router branches is not attempted — reference checks are existence-only.
Development
npm install
npm test # offline tests — synthetic blueprints built in-suite
npm run build # tsc → dist/
node scripts/smoke.mjs # end-to-end: generates a blueprint, drives the server over stdioArchitecture: src/blueprint.ts (recursive module walk, reference extraction, secret masking) and src/audit.ts (checks) are pure logic; src/index.ts is the MCP wiring. Zero runtime deps beyond the MCP SDK.
Not affiliated with or endorsed by Make / Celonis.
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityAmaintenanceLocal-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes scan, explanation, and fix-planning tools to MCP clients; modifies nothing and makes no outbound requests by default.3632MIT
- Alicense-qualityAmaintenanceSecurity scanner for MCP servers — vet an MCP before you wire it into an agent. Detects prompt-injection, credential exfiltration (via taint analysis), RCE, and supply-chain risks, and catches cross-server exfil chains no single server reveals. Zero-dependency local CLI, SARIF output, CI-gateable, no account.43MIT
- Alicense-qualityBmaintenanceStatically analyzes exported n8n automation workflows for security issues and returns structured findings.MIT
- Flicense-qualityBmaintenanceAudits GitHub Actions workflow files for supply-chain risks like script injection, leaked tokens, unpinned actions, and broad permissions.
Related MCP Connectors
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/arose26/make-audit-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server