audit_mcp_server_config
Audit MCP configuration files for security risks such as tool poisoning, hidden instructions, hardcoded credentials, unpinned packages, insecure transport, and dangerous tool combinations. Works fully offline.
Instructions
Audit an MCP client configuration for security risks — works offline, no external service required. Detects: tool poisoning, hidden/coercive instructions in tool descriptions, hardcoded credentials, unpinned packages (rug-pull risk), insecure transport, and toxic capability combinations (shell + network, file-read + network).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| config_json | Yes | The FULL JSON content of the MCP config file as a string (e.g. claude_desktop_config.json or .mcp.json). Paste the file content, not the path. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |