🛡️
MCPAudit.pro
OWASP MCP Security Benchmark & Hardening Suite

Audit, Harden & Defend Your
Model Context Protocol Servers

AI agents in Claude, Cursor, and Zed execute commands with dangerous permissions. Scan for prompt injection, arbitrary bash execution, path traversal, and secret leaks in seconds.

Live Interactive MCP Security Scanner

Paste a tool definition, system prompt, or `mcpServers` config to run an immediate security audit.

Load sample:
⚡ Evaluated locally against OWASP MCP Top 10 rules. Zero data retained.

The OWASP MCP Top 10 Threat Model

Model Context Protocol servers operate with autonomous agency. A single prompt injection in web content or email can trick the agent into executing catastrophic actions.

MCP-SEC-001 • CRITICAL

Arbitrary Command Execution

Tools running bash or shell interpreters without strict allowlisting allow attackers to inject malicious shell operators.

MCP-SEC-002 • CRITICAL

Path Traversal & System Reads

Unsandboxed filesystem tools let agents traverse outside working directories (`../../etc/shadow` or `.env` files).

MCP-SEC-005 • CRITICAL

Credential Exposure in Configs

API keys, bearer tokens, and DB connection strings hardcoded inside `claude_desktop_config.json` without env vaults.

MCP-SEC-006 • HIGH

Indirect Prompt Injection

Hostile content in webpages or emails overrides model system instructions and instructs the agent to misuse tools.

MCP-SEC-007 • HIGH

Destructive Excessive Agency

High-impact actions (DROP database, delete file, execute transaction) executed without explicit user confirmation.

MCP-SEC-008 • MEDIUM

Tool Output Secret Reflection

Tools echoing internal API tokens, passwords, or PII into the LLM conversation context, resulting in data exfiltration.

Simple, Transparent Pricing

Secure Your AI Agents Today

One-time purchase. Lifetime updates. Zero recurring subscription traps.

Most Popular

Solo Developer Edition

For indie hackers and developers building MCP servers.

$29 USD / one-time
  • ✓ Full `mcpaudit` CLI (unlimited local scans)
  • ✓ Python Guardrail Middleware (`@mcp_guard`)
  • ✓ Node.js/TypeScript Middleware (`wrapMcpTool`)
  • ✓ OWASP MCP Compliance Report Generator (HTML/MD)
  • ✓ 3 Production-Hardened MCP Starters (Postgres, FS, API)
  • ✓ 1 Developer Commercial License & Lifetime Updates
Buy Solo Developer Pack ($29)

Instant digital delivery • 30-day money-back guarantee

Team & Commercial Edition

For startups and engineering teams deploying agent workflows.

$59 USD / one-time
  • ✓ Everything in Solo Developer Edition
  • ✓ Multi-seat commercial organization license
  • ✓ GitHub Actions CI/CD automated PR scanner
  • ✓ Team Threat Model & Security Policy Templates
  • ✓ Priority email support & architecture review
Buy Team License ($59)

Instant digital delivery • Receipt / VAT invoice provided