Developer · Local MCP server
MCP Config Auditor
Scans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.4hmetuyar/mcp-config-auditor- Version
- 0.3.1
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-09-28
- Updated
- 2026-09-28
- Publisher
- 4hmetuyar (GitHub) · 26 servers with pages here
- Listed under
- VS Code MCP servers
- Repository
- github.com/GuardBee/guardbee-mcp (folder packages/mcp-config-auditor)
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @guardbee/mcp-config-auditor | 0.3.1 | stdio |
How to connect MCP Config Auditor
MCP Config Auditor runs locally from a Node.js package published to the npm registry: @guardbee/mcp-config-auditor version 0.3.1. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-config-auditor@0.3.1.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"mcp-config-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-config-auditor@0.3.1"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from 4hmetuyar (GitHub)
| Server | Runs |
|---|---|
| Compliance CheckerKVKK/GDPR/CCPA compliance checks for codebases. | Local · stdio |
| Db GatewayKVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log. | Local · stdio |
| Dependency AuditorCVE scanning for npm/pip/cargo dependencies via OSV. | Local · stdio |
| Dns IntelligenceDNS record enumeration, misconfiguration and dangling-subdomain detection. | Local · stdio |
| Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs. | Local · stdio |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | Local · stdio |
| MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets. | Local · stdio |
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | Local · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Local · stdio |
| Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience. | Local · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | Local · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| MCP Code Review ServerCode review as an MCP server — structured reviews with OWASP security scanning. | Local · stdio |
| MCP Code SanitizerStrict AI code reviewer powered by Groq. Finds bugs and vulnerabilities. | Local · stdio |
| MCP CodeauditSecurity audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV. | Local · stdio |
| MCP Commerce Server StarterFastMCP commerce server starter: product catalog, search, and checkout. Deploy to Vercel in 5 min. | Remote · HTTP |
| MCP ConfirmAn MCP server whose confirmation cannot be replayed against a different call. | Local · stdio |
| MCP Context CardMCP server for a project's context (AGENTS.md), memory, and identity — base or drop-in extension. | Local · stdio |
| MCP Croit CephMCP server for Croit Ceph cluster management with dynamic OpenAPI tool generation. | Local · stdio |
| MCP CulqiMCP server for Culqi — Peru PSP: charges, refunds, cards, Yape/PagoEfectivo, subscriptions. | Local · stdio |