
MCP Security Guard
io.github.petrovicistefanv0.7.0更新于 Oct 6, 2026
Audit MCP servers for tool poisoning, rug pulls and supply-chain risk (OWASP MCP Top 10).
概览
审计已安装的 MCP 服务器,检查工具投毒、隐藏文本、rug pull、危险能力与供应链风险,并提供可选的运行时钩子。
- 功能
- 发现 Claude Code、Claude Desktop、插件及其他本地客户端中配置的 MCP 服务器,并审计其工具定义、说明、提示词和资源,检查投毒、隐藏字符、工具遮蔽和名称冲突。它按哈希固定工具定义以发现后续改动,为每个服务器评分并归类执行、写入、删除、外发等能力。可选钩子会在 MCP 调用中提示凭据或注入指令,并记录不含内容的审计日志。发现项会标注 OWASP MCP Top 10 编号,可导出为 markdown、JSON、SARIF 或 HTML。
- 适用场景
- 当你安装了多个 MCP 服务器,想了解它们能做什么、其描述是否被篡改时使用。它适合在安装前审查某个服务器、固定定义以便日后发现改动,以及在 CI 中执行已批准服务器策略。
- 运行要求
- 以 npm 包通过 stdio 在本地运行,通常用 npx,免费功能无需账号或 API 密钥。进行工具级审计需要启动服务器并显式确认;可选的供应链检查需要访问 npm、PyPI 和 OSV 的网络。付费方案使用 MCP_SECURITY_API_KEY。
安装
在 SourceWeft 中
- 打开 控制台中的 MCP Security Guard,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
mcp-security-guard
A Claude Code plugin that audits the MCP servers you have installed. Your code is covered by other tools. This one checks the servers that inject text into Claude's context.
It discovers servers from every place Claude Code and Claude Desktop load them: user, local and project scope, servers shipped inside installed plugins and plugins synced from your claude.ai account (named <plugin>:<server>), claude_desktop_config.json and Claude Desktop extensions, the organisation-managed managed-mcp.json, other clients on the machine (Cursor, VS Code, Windsurf, user and project configs), and the claude.ai connectors you have used (names only: their configuration lives in your account).
It scans everything a server puts into Claude's context, not only tools: server instructions, prompts, resources and resource templates go through the same poisoning checks and are pinned for rug-pull detection.
Everything runs locally. Nothing is sent anywhere.
OWASP MCP Top 10 coverage
Every finding is tagged with its OWASP MCP Top 10 id, in reports and in SARIF.
What a local tool cannot do (planned for a hosted Team plan): org-wide discovery and audit aggregation, and OAuth scope review.
Measured: detects 26/27 attacks from a corpus of publicly documented techniques, with 0 false positives on 13 hard benign samples and on 17 real servers (83 tools). See bench/RESULTS.md.
Install
Then run /mcp-audit, or ask Claude "are my MCP servers safe?".
Other MCP clients (Cursor, VS Code, Windsurf, Claude Desktop, Cline, ...)
The same server is published on npm and runs with no install step:
The command line tool is the same package: npx mcp-security-guard audit --project-only. It is also listed in the official MCP Registry as io.github.petrovicistefan/mcp-security-guard.
Tools
Session-start check
A SessionStart hook re-verifies only the servers you have pinned (pinning is your consent to launch them) and stays silent unless something changed. Control it with MCP_SECURITY_SESSION_CHECK:
full(default): compare launch configs and re-list toolsconfig: compare launch configs only, launch nothingoff: disable the check
CI / GitHub Action
Fail pull requests that add risky MCP servers to .mcp.json, and show the findings in GitHub code scanning:
The same checks run locally without Claude:
Check a server before installing it (launches it, sends only initialize and tools/list):
Test your own server for command injection and path traversal (it calls the tools; run a test instance, ideally in a container):
Fix what the audit found (dry run first, then --write):
Start a team policy from the servers configured today:
Any command takes --format markdown|json|sarif|html. The HTML report is a single self-contained file you can open in a browser or attach to a ticket.
Exit codes: 0 clean, 1 findings at or above --fail-on, 2 usage error.
Limitations
Remote servers that require OAuth (most hosted MCP servers) cannot be scanned at the tool level: the scanner cannot reuse Claude Code's tokens. Their configuration is still audited.
Interactive dashboard (MCP App)
security_dashboard is an MCP App: hosts that support MCP Apps (Claude Desktop, claude.ai, VS Code Copilot…) render it inline. It shows every server with its score and grade, findings filterable by severity and server, the OWASP MCP Top 10 breakdown, recommended permission rules, and Full scan and Pin buttons. Selecting a server tells Claude what you are looking at, so follow-up questions have context. Claude Code in a terminal gets the text summary instead.
To use it in Claude Desktop, add the server to claude_desktop_config.json and ask Claude to "open the MCP security dashboard":
The UI is a single self-contained HTML file. Server-supplied text reaches the page only as text (never as HTML), and the host's sandbox applies. Develop it with a local host that drives the real server: npm run dashboard:dev -- /path/to/project.
Runtime hooks
The hooks add about 40 ms per MCP call.
Trust model
- Read-only, apart from the pin file, the audit log, and
policy-init(which writes a file you asked for). - Network only when you opt in:
check_supply_chain/--supply-chainsend package names and versions to npm, PyPI and OSV. Theadversarial_testtool is the only one that calls tools. - Evidence from scanned servers is sanitised (invisible characters revealed, length capped) and labelled as untrusted data.
- Secrets are masked in all output.
- Static checks reduce risk. They do not prove a server safe: malicious behaviour in tool responses or server code is out of scope.
Development
test/fixtures/poisoned-server.mjs is a deliberately malicious server used by the end-to-end test.
Pro & Team (early access)
Everything above is free and stays free: it runs locally and needs no account. Paid plans add what needs a server: a daily threat feed of known malicious MCP servers and packages, alerts when a server you use ships changed tool descriptions, history, and team policies and dashboards. They are opt-in through MCP_SECURITY_API_KEY; see PRIVACY.md for exactly what is sent.
Interested? Join the early access list. Early sign-ups get launch pricing, including a limited lifetime license.
Security, privacy, license
- Found a vulnerability? See SECURITY.md.
- What is read, written and sent: PRIVACY.md.
- Changes: CHANGELOG.md.
- MIT, see LICENSE.
About the author
I'm Stefan Petrovici: passionate about IT, a husband and a father. I built mcp-security-guard on my own. I'm looking for a job.
I build web applications end to end, frontend, backend, APIs and deployment, and I'm happy to work on anything else that needs building. This repository shows how I work: tests, CI, careful documentation and attention to security.
I also build WordPress and WooCommerce plugins, available at pluginsforstores.com.
If your team is hiring, write to me at [email protected].
来源:README.md,提交 dbc07be
工具
0版本历史
1- v0.7.0最新Oct 6, 2026


