Track MCP LogoTrack MCP
Track MCP LogoTrack MCP

The world's largest repository of Model Context Protocol servers. Discover, explore, and submit MCP tools.

Product

  • Categories
  • Top MCP
  • New & Updated
  • Submit MCP

Company

  • About

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 TrackMCP. All rights reserved.

Built with ❤️ by Krishna Goyal

    Mcp Security Audit

    A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.

    46 stars
    TypeScript
    Updated Oct 29, 2025
    audit
    model-context-protocol
    npm
    security

    Table of Contents

    • Features
    • Installing via Smithery
    • MCP Integration
    • Option 1: Using NPX (Recommended)
    • Option 2: Download Source Code and Configure Manually
    • Configuration Screenshots
    • Cursor Configuration
    • Cline Configuration
    • API Response Format
    • Response Examples
    • 1. When Vulnerabilities Found (Severity-response.json)
    • 2. When No Vulnerabilities Found (no-Severity-response.json)
    • Development
    • Contributing
    • License
    • Author
    • Links

    Table of Contents

    • Features
    • Installing via Smithery
    • MCP Integration
    • Option 1: Using NPX (Recommended)
    • Option 2: Download Source Code and Configure Manually
    • Configuration Screenshots
    • Cursor Configuration
    • Cline Configuration
    • API Response Format
    • Response Examples
    • 1. When Vulnerabilities Found (Severity-response.json)
    • 2. When No Vulnerabilities Found (no-Severity-response.json)
    • Development
    • Contributing
    • License
    • Author
    • Links

    Documentation

    Security Audit Tool

    smithery badge

    NPM version

    License: MIT

    A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.

    Features

    • 🔍 Real-time security vulnerability scanning
    • 🚀 Remote npm registry integration
    • 📊 Detailed vulnerability reports with severity levels
    • 🛡️ Support for multiple severity levels (critical, high, moderate, low)
    • 📦 Compatible with npm/pnpm/yarn package managers
    • 🔄 Automatic fix recommendations
    • 📋 CVSS scoring and CVE references

    Installing via Smithery

    To install Security Audit Tool for Claude Desktop automatically via Smithery:

    bash
    npx -y @smithery/cli install @qianniuspace/mcp-security-audit --client claude

    MCP Integration

    Option 1: Using NPX (Recommended)

    1. Add MCP configuration to Cline /Cursor:

    json
    {
      "mcpServers": {
        "mcp-security-audit": {
          "command": "npx",
          "args": ["-y", "mcp-security-audit"]
        }
      }
    }

    Option 2: Download Source Code and Configure Manually

    1. Clone the repository:

    bash
    git clone https://github.com/qianniuspace/mcp-security-audit.git
    cd mcp-security-audit

    2. Install dependencies and build:

    bash
    npm install
    npm run build

    3. Add MCP configuration to Cline /Cursor :

    json
    {
      "mcpServers": {
        "mcp-security-audit": {
          "command": "npx",
          "args": ["-y", "/path/to/mcp-security-audit/build/index.js"]
        }
      }
    }

    Configuration Screenshots

    Cursor Configuration

    Cursor Configuration

    Cline Configuration

    Cline Configuration

    API Response Format

    The tool provides detailed vulnerability information including severity levels, fix recommendations, CVSS scores, and CVE references.

    Response Examples

    1. When Vulnerabilities Found (Severity-response.json)

    json
    {
      "content": [{
        "vulnerability": {
          "packageName": "lodash",
          "version": "4.17.15",
          "severity": "high",
          "description": "Prototype Pollution in lodash",
          "cve": "CVE-2020-8203",
          "githubAdvisoryId": "GHSA-p6mc-m468-83gw",
          "recommendation": "Upgrade to version 4.17.19 or later",
          "fixAvailable": true,
          "fixedVersion": "4.17.19",
          "cvss": {
            "score": 7.4,
            "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
          },
          "cwe": ["CWE-1321"],
          "url": "https://github.com/advisories/GHSA-p6mc-m468-83gw"
        },
        "metadata": {
          "timestamp": "2024-04-23T10:00:00.000Z",
          "packageManager": "npm"
        }
      }]
    }

    2. When No Vulnerabilities Found (no-Severity-response.json)

    json
    {
      "content": [{
        "vulnerability": null,
        "metadata": {
          "timestamp": "2024-04-23T10:00:00.000Z",
          "packageManager": "npm",
          "message": "No known vulnerabilities found"
        }
      }]
    }

    Development

    For development reference, check the example response files in the public directory:

    • Severity-response.json : Example response when vulnerabilities are found (transformed from npm audit API response)
    • no-Severity-response.json : Example response when no vulnerabilities are found (transformed from npm audit API response)

    Note: The example responses shown above are transformed from the raw npm audit API responses to provide a more structured format. The original npm audit API responses contain additional metadata and may have a different structure.

    Contributing

    Contributions are welcome! Please read our Contributing Guide for details on our code of conduct and the process for submitting pull requests.

    License

    This project is licensed under the MIT License - see the LICENSE file for details.

    Author

    ESX (qianniuspace@gmail.com)

    Links

    • GitHub Repository
    • Issue Tracker
    • Changelog
    code
    // Code block

    Similar MCP

    Based on tags & features

    • AN

      Anilist Mcp

      TypeScript·
      57
    • ME

      Metmuseum Mcp

      TypeScript·
      14
    • MC

      Mcp Ipfs

      TypeScript·
      11
    • OP

      Openai Gpt Image Mcp

      TypeScript·
      75

    Trending MCP

    Most active this week

    • PL

      Playwright Mcp

      TypeScript·
      22.1k
    • SE

      Serena

      Python·
      14.5k
    • MC

      Mcp Playwright

      TypeScript·
      4.9k
    • MC

      Mcp Server Cloudflare

      TypeScript·
      3.0k
    View All MCP Servers

    Similar MCP

    Based on tags & features

    • AN

      Anilist Mcp

      TypeScript·
      57
    • ME

      Metmuseum Mcp

      TypeScript·
      14
    • MC

      Mcp Ipfs

      TypeScript·
      11
    • OP

      Openai Gpt Image Mcp

      TypeScript·
      75

    Trending MCP

    Most active this week

    • PL

      Playwright Mcp

      TypeScript·
      22.1k
    • SE

      Serena

      Python·
      14.5k
    • MC

      Mcp Playwright

      TypeScript·
      4.9k
    • MC

      Mcp Server Cloudflare

      TypeScript·
      3.0k