apisec-inc/mcp-audit

See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.

54
/ 100
Established

This tool helps security and compliance teams understand what information their AI agents can access before deployment. It scans configuration files from AI development tools to identify exposed secrets, API endpoints, and AI models. The output is a clear report, including AI-BOMs, that pinpoints potential security risks, enabling teams to remediate issues and ensure compliance.

143 stars.

Use this if you need to audit your AI development environment for security vulnerabilities and ensure your AI agents aren't exposing sensitive data or connecting to unauthorized services.

Not ideal if you're looking for a runtime monitoring solution or need to scan secrets stored in dedicated secrets managers or dynamically generated configurations.

AI-security compliance risk-management API-governance data-privacy
No Package No Dependents
Maintenance 10 / 25
Adoption 10 / 25
Maturity 13 / 25
Community 21 / 25

How are scores calculated?

Stars

143

Forks

35

Language

Python

License

MIT

Last pushed

Feb 27, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/apisec-inc/mcp-audit"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.