
Latchpoint
io.github.robyrorov0.1.1更新于 Oct 9, 2026
Offline, read-only auditing of MCP client configuration files with redacted findings
概览
让助手以离线、只读方式审计 MCP 客户端配置文件,并返回已脱敏的发现结果,可输出为文本、JSON 或 SARIF。
- 功能
- Latchpoint 扫描 MCP 客户端配置文件,但不会运行其中配置的服务器。它提供 list_rules 和 scan 两个工具,检查的规则包括非回环端点使用明文 HTTP、shell 包装器、未固定版本的 npx 或 uvx 包、字面量凭据、过宽的文件系统范围、通配主机以及无效的传输设置。每条发现都带有稳定的规则 ID、严重级别、位置、修复建议、已脱敏证据,以及在解释依赖被启动服务器时给出的置信度说明。结果可输出为文本、JSON 或 SARIF。
- 适用场景
- 当你希望在安装服务器前后检查 MCP 客户端配置文件中的风险模式,或把配置检查加入构建流程时,可以使用它。它适合对本地配置做防御性审查,而不是对服务器做运行时测试。
- 运行要求
- 本地需要 Python 3.11 或更高版本;可从 PyPI 安装 mcp-latchpoint,或用 uvx 运行。stdio 服务器启动时必须通过 --root 指定允许的根目录,相对扫描路径会在该根目录下解析。未声明需要账户、API 密钥或网络访问。
安装
在 SourceWeft 中
- 打开 控制台中的 Latchpoint,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
mcp-latchpoint
mcp-latchpoint audits MCP client configuration files without running the configured servers. It works offline, reads only local files you select, and produces text, JSON, or SARIF results.
This is an early defensive tool. Review findings in context before changing a working configuration.
What it checks
The v0.1 rules cover:
- plain HTTP for non-loopback remote endpoints
- shell wrappers and inline shell control syntax
- identifiable
npxanduvxpackages without exact versions - literal credentials in environment values, headers, arguments, or URLs
- filesystem roots and home roots passed as recognizable access scopes
- wildcard hosts and recognizable wildcard scopes
- conflicting, missing, invalid, or unsupported transport settings
Every finding has a stable rule ID, severity, location, remediation, redacted evidence, and a confidence note when interpretation depends on the launched server.
Install
Python 3.11 or newer is required.
To install from a local checkout:
For development:
The MCP server uses the official Python SDK v2 and the dependency is constrained to mcp>=2.3,<3.
CLI
Scan one or more explicit files:
Restrict every explicit path to an approved directory:
Directories are searched only for recognized MCP config filenames, up to 256 files. A file is limited to 1 MiB by default. Change these bounds with --max-files and --max-bytes.
Exit codes are 0 for a completed scan below the chosen threshold, 1 when a finding meets --fail-on, and 2 for input, containment, or parse errors. The default --fail-on none reports findings without failing a build.
List and explain rules:
Recognized layouts
Explicit files may use these structures:
Files ending in .jsonc are also parsed as JSONC. Other .json files remain strict JSON so malformed input is not silently accepted.
--discover checks only the following paths when they exist. It does not search the rest of the home directory.
- All systems:
~/.claude.json,~/.cursor/mcp.json,~/.codex/config.toml,$COPILOT_HOME/mcp-config.jsonwith~/.copilot/mcp-config.jsonas the fallback - Current project:
.mcp.json,.codex/config.toml,.cursor/mcp.json,.vscode/mcp.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json,%APPDATA%\Code\User\mcp.json - macOS:
~/Library/Application Support/Claude/claude_desktop_config.json,~/Library/Application Support/Code/User/mcp.json - Linux:
$XDG_CONFIG_HOME/Code/User/mcp.json, falling back to~/.config/Code/User/mcp.json
Read-only MCP server
The stdio server exposes two tools: list_rules and scan. It requires an allowed root at startup. Relative scan paths are resolved below that root; absolute paths, .. traversal, and symlinks cannot escape it.
Example client entry:
The server returns findings and scan metadata, never raw configuration content. Stdio is the only server transport exposed by the entry point, and stdout is reserved for MCP protocol messages.
The serve command is also the entry point advertised in the MCP Registry. Set --root to a directory you explicitly trust before connecting a client.
Glama build
The Glama listing builds a container from the repository. In its Dockerfile configuration, use Python 3.13, these build steps and command arguments:
The root is an existing directory with synthetic sample configurations. It lets Glama start and inspect the tools without giving the server access to a user's files. The command uses the executable inside the virtual environment created by uv sync. For this demo, the environment-variable schema can be {"type":"object","properties":{}} and placeholder parameters can be {}.
To scan your own configurations, run the server locally with --root pointing to a directory you explicitly trust. Glama's demo root is only for the sample files in examples/.
Safety and limitations
The scanner never executes commands, installs packages, resolves referenced environment variables, or connects to endpoints. It does not follow configuration includes or inspect an MCP server's code or runtime behavior. Argument-based rules are intentionally limited to recognizable patterns, so custom flags can be missed. A clean report is not proof that a server is safe.
Secret detection is designed to emit field names and <redacted> markers rather than values. If you find a leak or a path-containment problem, follow SECURITY.md and do not attach a real configuration to a public issue.
License
MIT. See LICENSE.
来源:README.md,提交 b5f65df
工具
0版本历史
1- v0.1.1最新Oct 9, 2026

