Sviluppo · Server MCP locale
A2a Auditor
Scans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposure.
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
io.github.4hmetuyar/a2a-auditor- Versione
- 0.1.1
- Stato
- Attivo
- Categoria
- sviluppo
- Trasporto
- stdio (processo locale)
- Pacchetto
- npm
- Pubblicato
- 28 settembre 2026
- Aggiornato
- 28 settembre 2026
- Editore
- 4hmetuyar (GitHub) · 26 server con una pagina qui
- Namespace
- Namespace verificato dal MCP Registry tramite GitHub (github.com/4hmetuyar) · come funziona
- Repository
- github.com/GuardBee/guardbee-mcp (cartella packages/a2a-auditor)
- Fonte
- Voce nell’API del registro
Pacchetti
| Registro | Pacchetto | Versione | Trasporto |
|---|---|---|---|
| npm | @guardbee/mcp-a2a-auditor | 0.1.1 | stdio |
Come collegare A2a Auditor
A2a Auditor viene eseguito in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @guardbee/mcp-a2a-auditor, versione 0.1.1. Comunica via MCP su stdio, quindi il client lo avvia come programma e dialoga con esso tramite standard input e standard output. Richiede Node.js; i client in genere lo avviano con npx - il comando abituale è npx -y @guardbee/mcp-a2a-auditor@0.1.1.
Nel formato JSON mcpServers, letto da molti client MCP desktop e per editor di codice, la voce si presenta così (segnaposto tra parentesi angolari):
{
"mcpServers": {
"a2a-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-a2a-auditor@0.1.1"
]
}
}
}Ricavato dalla voce del registro, non testato qui. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server di 4hmetuyar (GitHub)
| Server | Esecuzione |
|---|---|
| Agent Graph AuditorFinds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphs. | Locale · stdio |
| Ai Code ScannerScans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injection. | Locale · stdio |
| Compliance CheckerKVKK/GDPR/CCPA compliance checks for codebases. | Locale · stdio |
| Db GatewayKVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log. | Locale · stdio |
| Dependency AuditorCVE scanning for npm/pip/cargo dependencies via OSV. | Locale · stdio |
| Dns IntelligenceDNS record enumeration, misconfiguration and dangling-subdomain detection. | Locale · stdio |
| Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs. | Locale · stdio |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | Locale · stdio |
| MCP Config AuditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats. | Locale · stdio |
| MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets. | Locale · stdio |
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | Locale · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Locale · stdio |
Altri server della categoria sviluppo
| Server | Esecuzione |
|---|---|
| 402cronPaid cron for AI agents: we call your https URL on schedule, signed. No account, paid with x402. | Remoto · HTTPVerifica live: ✓ handshake |
| 4da MCP ServerUpgrade intelligence for AI agents: what an upgrade changes, where it touches your code, CVE scans. | Locale · stdio |
| 4q TokenzMCP proxy that reduces token usage by exposing only mcp_search and mcp_call. | Locale · stdio |
| 7IT SolutionsStore speed, web-app security checks, automation ROI, checklists and guides from 7IT Solutions. | Remoto · HTTPVerifica live: ✓ handshake |
| A2adependencyinspector MCPRemote MCP for A2A dependency inspector MCP, structured receipts, audit logs, and reviewer-ready evi. | Remoto · HTTPVerifica live: ✗ nessun handshake |
| A2ahubReliable handoffs between autonomous agents, using a Git repository both sides can inspect. | Locale · stdio |
| A2AL DaemonMakes any AI agent globally reachable and discoverable-no cloud, domain, or port forwarding needed. | Locale · stdio |
| A2AParkPublic behavioral test environment for AI agents with stateful rides and signed scorecards. | Remoto · HTTPVerifica live: ✓ handshake |