Audit MCP configuration
audit_mcp_configStatically checks MCP server configuration for plaintext secrets, insecure HTTP, unpinned packages, risky Docker, pipe-to-shell commands, and duplicate names; launches nothing.
Instructions
Static audit of MCP server configuration: plaintext secrets in env/headers/args/URLs, plain-HTTP remote servers, unpinned npx/uvx packages, unpinned or privileged Docker containers, pipe-to-shell launch commands, and duplicate server names across scopes. Read-only; launches nothing.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| project_dir | No | Project directory. Defaults to the current project. |