Static AST security scanner detecting command injection, leaked secrets, and SSRF in MCP tools.
Run one of the commands below, then add the client config underneath.
Streamable HTTPhttps://neon_innovation_lab--mcp-security-auditor.apify.actor/mcpSSEhttps://neoninnovationlab.com/api/mcp-security
Paste into Claude Desktop, Cursor (mcp.json), VS Code or any MCP client, then restart the client.
mcpServers{
"mcpServers": {
"mcp-security-auditor": {
"url": "https://neon_innovation_lab--mcp-security-auditor.apify.actor/mcp"
}
}
}
MCP Security & Vulnerability Auditor is listed in the Security category of the MCPNav directory. It is distributed as Streamable HTTP, SSE and can be loaded by any client that speaks the Model Context Protocol.
Typical uses include giving your assistant scoped access to the corresponding service so it can answer questions and take actions with real data instead of guessing. Always review what a server can access before you enable it — see our MCP security guide.
MCP Security & Vulnerability Auditor is an MCP server by Ansarii. Static AST security scanner detecting command injection, leaked secrets, and SSRF in MCP tools.
Install it with: https://neon_innovation_lab--mcp-security-auditor.apify.actor/mcp. Then add the JSON config to your client's MCP settings and restart the client.
The MCP server itself is free to install. The source is public on https://github.com/Ansarii/mcp-security-auditor. Any third-party API it calls (such as a search or maps API) may require its own key and billing.
Any MCP-compatible client can use it, including Claude Desktop, Cursor, VS Code, Windsurf and custom agents.