Developer · Local MCP server

MCP Config Auditor

Scans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.4hmetuyar/mcp-config-auditor
Version
0.3.1
Status
Active
Category
developer
Transport
stdio (local process)
Package
npm
Published
2026-09-28
Updated
2026-09-28
Publisher
4hmetuyar (GitHub) · 26 servers with pages here
Listed under
VS Code MCP servers
Repository
github.com/GuardBee/guardbee-mcp (folder packages/mcp-config-auditor)
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
npm@guardbee/mcp-config-auditor0.3.1stdioNone declared

How to connect MCP Config Auditor

MCP Config Auditor runs locally from a Node.js package published to the npm registry: @guardbee/mcp-config-auditor version 0.3.1. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-config-auditor@0.3.1.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "mcp-config-auditor": {
      "command": "npx",
      "args": [
        "-y",
        "@guardbee/mcp-config-auditor@0.3.1"
      ]
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from 4hmetuyar (GitHub)

All 26 →
ServerRunsEndpoint or package
Compliance CheckerKVKK/GDPR/CCPA compliance checks for codebases.Local · stdionpm: @guardbee/mcp-compliance-checker
Db GatewayKVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log.Local · stdionpm: @guardbee/mcp-db-gateway
Dependency AuditorCVE scanning for npm/pip/cargo dependencies via OSV.Local · stdionpm: @guardbee/mcp-dependency-auditor
Dns IntelligenceDNS record enumeration, misconfiguration and dangling-subdomain detection.Local · stdionpm: @guardbee/mcp-dns-intelligence
Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs.Local · stdionpm: @guardbee/mcp-elicitation-auditor
Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints.Local · stdionpm: @guardbee/mcp-llm-redteam
MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets.Local · stdionpm: @guardbee/mcp-server-auditor
Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory.Local · stdionpm: @guardbee/mcp-memory-poisoning-scanner
Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks.Local · stdionpm: @guardbee/mcp-model-scanner
Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience.Local · stdionpm: @guardbee/mcp-oauth-auditor
Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection.Local · stdionpm: @guardbee/mcp-prompt-injection-scanner
Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts.Local · stdionpm: @guardbee/mcp-prompt-leak-scanner

More developer servers

All 6,250 →
ServerRunsEndpoint or package
MCP Code Review ServerCode review as an MCP server — structured reviews with OWASP security scanning.Local · stdioPyPI: aicraft-code-review
MCP Code SanitizerStrict AI code reviewer powered by Groq. Finds bugs and vulnerabilities.Local · stdioPyPI: mcp-code-sanitizer
MCP CodeauditSecurity audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.Local · stdionpm: @infoinlet/mcp-codeaudit
MCP Commerce Server StarterFastMCP commerce server starter: product catalog, search, and checkout. Deploy to Vercel in 5 min.Remote · HTTPmcp-commerce-starter.vercel.app
MCP ConfirmAn MCP server whose confirmation cannot be replayed against a different call.Local · stdioPyPI: mcp-confirm
MCP Context CardMCP server for a project's context (AGENTS.md), memory, and identity — base or drop-in extension.Local · stdionpm: mcp-context-card
MCP Croit CephMCP server for Croit Ceph cluster management with dynamic OpenAPI tool generation.Local · stdioOCI image (Docker): docker.io/croit/mcp-croit-ceph:0.2.16
MCP CulqiMCP server for Culqi — Peru PSP: charges, refunds, cards, Yape/PagoEfectivo, subscriptions.Local · stdionpm: @codespar/mcp-culqi