Metadata-Version: 2.4
Name: readystack-mcp-config-audit
Version: 1.0.7.post1
Summary: Audit one mcp.json for what an agent config gives away — inline API keys, unpinned npx launches, plaintext remote servers, shell wrappers, auto-approved tools, whole-machine filesystem roots — with li (bundled Node.js runtime)
Author-email: ReadyStack <support@getreadystack.com>
License: Proprietary - see LICENSE.txt
Project-URL: Homepage, https://getreadystack.com/tools/mcp-config-audit?ref=pypi
Project-URL: Documentation, https://getreadystack.com/tools/mcp-config-audit?ref=pypi
Project-URL: Support, https://getreadystack.com/support
Keywords: mcp,mcp.json,model context protocol,ai agent,security,copilot,cursor,claude
Classifier: Programming Language :: Python :: 3
Classifier: Environment :: Console
Classifier: Topic :: Software Development :: Quality Assurance
Classifier: Operating System :: OS Independent
Requires-Python: >=3.9
Description-Content-Type: text/markdown
License-File: LICENSE.txt
Requires-Dist: nodejs-wheel-binaries>=20
Dynamic: license-file

# MCP Server Config Audit

> Runs the same checker as the npm package `@readystack/mcp-config-audit` on a Node.js runtime that pip installs for you (`nodejs-wheel-binaries`) - no system Node.js needed. Your files are checked locally.

Audit one mcp.json for what an agent config gives away — inline API keys, unpinned npx launches, plaintext remote servers, shell wrappers, auto-approved tools, whole-machine filesystem roots — with line numbers. The shipped sample config _fixtures/dirty.mcp.json (33 lines, five servers) returns 14 findings, 8 of them blocking.

## Install

```
mcp-config-audit file
```

Node 18+. The same 18 rules as the VS Code extension, from a terminal or CI.

## Free

- Audit one mcp.json against all 18 rules and get every inline credential, unpinned launch and over-broad grant named with its line number and its replacement. The extension ships a sample config, _fixtures/dirty.mcp.json, 33 lines and five servers, which returns 14 findings, 8 of them blocking, and its corrected twin _fixtures/clean.mcp.json, which returns zero.
- `--rules` lists every rule

## With a licence ($29 once)

- Audit every agent config in a repository and in the user-scope locations for VS Code, Cursor, Claude Desktop and Windsurf in one pass, fail CI with a non-zero exit code on any blocker, and export a dated evidence report of file, rule and line.

```
@readystack/mcp-config-audit --dir ./templates --report html --out report.html
```

Freelance application-security engineers commonly bill $100-$200 an hour; a single review hour costs more than three licences, and the config changes every time somebody adds a server.

## Use from an AI agent (MCP)

Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:

```json
{ "mcpServers": { "mcp-config-audit": { "command": "npx", "args": ["-y", "@readystack/mcp-config-audit", "--mcp"] } } }
```

Tools: `check_text` and `check_file` (free) · `check_dir` (licence). The agent gets every finding with the line number.

## Use in CI

```yaml
- name: MCP Server Config Audit
  run: npx -y @readystack/mcp-config-audit --dir . --ci
```

(container: `docker run --rm -v "$PWD:/work" getreadystack/mcp-config-audit --dir /work --ci`)

The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set `READYSTACK_LICENSE=<key>` or run `--license <key>` once.

[Get a licence](https://getreadystack.com/api/buy/cl/polar_cl_9L57rNpRm9rHntAhalWjzrWXftaA8sLKSAxkv2n1SKA)


<!-- mcp.json security -->


## Install (PyPI)

```
pip install readystack-mcp-config-audit
mcp-config-audit --help
```
