Developer · Local MCP server

Unbounded Consumption Auditor

Scans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6)

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.4hmetuyar/unbounded-consumption-auditor
Version
0.1.2
Status
Active
Category
developer
Transport
stdio (local process)
Package
npm
Published
2026-09-28
Updated
2026-09-28
Publisher
4hmetuyar (GitHub) · 26 servers with pages here
Repository
github.com/GuardBee/guardbee-mcp (folder packages/unbounded-consumption-auditor)
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
npm@guardbee/mcp-unbounded-consumption-auditor0.1.2stdioNone declared

How to connect Unbounded Consumption Auditor

Unbounded Consumption Auditor runs locally from a Node.js package published to the npm registry: @guardbee/mcp-unbounded-consumption-auditor version 0.1.2. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-unbounded-consumption-auditor@0.1.2.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "unbounded-consumption-auditor": {
      "command": "npx",
      "args": [
        "-y",
        "@guardbee/mcp-unbounded-consumption-auditor@0.1.2"
      ]
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from 4hmetuyar (GitHub)

ServerRunsEndpoint or package
Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience.Local · stdionpm: @guardbee/mcp-oauth-auditor
Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection.Local · stdionpm: @guardbee/mcp-prompt-injection-scanner
Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts.Local · stdionpm: @guardbee/mcp-prompt-leak-scanner
Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval.Local · stdionpm: @guardbee/mcp-rug-pull-detector
Secret ScannerScans files for leaked secrets and API keys.Local · stdionpm: @guardbee/mcp-secret-scanner
Security ProxyMCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log.Local · stdionpm: @guardbee/mcp-security-proxy
Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence.Local · stdionpm: @guardbee/security-suite
Slopsquat ScannerChecks declared npm/PyPI dependencies against real registries to catch slopsquatting.Local · stdionpm: @guardbee/mcp-slopsquat-scanner
Tool Poisoning ScannerScans MCP tool definitions for hidden instructions and confused-deputy sinks.Local · stdionpm: @guardbee/mcp-tool-poisoning-scanner
Toxic Flow AuditorFinds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress.Local · stdionpm: @guardbee/mcp-toxic-flow-auditor
Vector Store ScannerProbes vector-database endpoints for unauthenticated exposure of embeddings/RAG data.Local · stdionpm: @guardbee/mcp-vector-store-scanner
Vulnerability ScannerTriggers GuardBee scans, queries findings, AI-assisted remediation guidance.Local · stdionpm: @guardbee/mcp-vulnerability-scanner

More developer servers

All 6,250 →
ServerRunsEndpoint or package
Umbryn MCPRedacts PII/PHI from text before it reaches an LLM. Fail-closed, self-hosted, no egress.Local · stdioPyPI: umbryn-mcp
uml.singsk.com PlantUMLRender, validate, encode/decode PlantUML diagram-as-code; 22 diagram types. Free, no auth.Remote · HTTPuml.singsk.com
Un Comtrade MCP ServerUN Comtrade international trade statistics via MCP. Country/HS lookups, flows, balances, rankings.Local · stdio, HTTPnpm: @cyanheads/un-comtrade-mcp-server
Un Datacommons MCPMCP server to query Data Commons indicators and observations (base or custom).Local · stdioPyPI: un-datacommons-mcp
Unchore DefendGrade a site's security headers with fixes and a badge; read logs or code for the defender.Local · stdioMCP Bundle (.mcpb): smilemino/unchore-defend/releases/download/v0.1.
UnClick669 apps and 1599 actions for any MCP agent, plus cross-session memory and QA passes.Remote · HTTPunclick.world
Understand Anything - MCPA MCP server for codebase architecture analysis and automated governance.Local · stdionpm: ua-mcp
Understand QuicklyPublic registry of code-knowledge graphs for AI agents with schema validation and drift detection.Local · stdionpm: @looptech-ai/understand-quickly-mcp