Back to Browse

Blast Radius MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Static blast-radius audit for MCP servers before agent install. Manifest optional.

About

Static blast-radius audit for MCP servers before agent install. Manifest optional.

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-designed security auditing tool for MCP servers with solid architecture and proper input validation. The codebase demonstrates good security practices: no hardcoded credentials, safe AST-based static analysis, and appropriate permission scoping. Minor findings include broad exception handling and limited validation in edge cases, but these do not constitute security vulnerabilities. The tool itself operates safely as a scanner and validator. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Default scan root when target_dir is omittedOptional

Environment variable: AOS_VALIDATOR_TARGET_DIR

JSONL path for local tool call log (never sent externally)Optional

Environment variable: AOS_VALIDATOR_MCP_LOG

Caller label (ci, smoke_self_call, etc.)Optional

Environment variable: AOS_VALIDATOR_CALLER

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-aos-standard-mcp-blast-radius": {
      "env": {
        "AOS_VALIDATOR_CALLER": "your-aos-validator-caller-here",
        "AOS_VALIDATOR_MCP_LOG": "your-aos-validator-mcp-log-here",
        "AOS_VALIDATOR_TARGET_DIR": "your-aos-validator-target-dir-here"
      },
      "args": [
        "mcp-blast-radius"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MCP Blast-Radius Auditor

AOS audited

See what any MCP server can actually touch — before you add it to your agent.

No manifest? You still get the full blast-radius report. Add a manifest to also catch divergences.

Also, if the server declares a manifest: Catch an MCP server that touches files it said it wouldn't — and block the merge in CI.

Statically extract what a third-party MCP server can reach (files, network, subprocess, env) via surface-level analysis. Compare against declared boundaries when a manifest is present.

Scan scope (default): production package only — excludes tests/, docs/, examples/, scripts/, benchmarks/, .github/, and test_*.py patterns; JSON output includes scan_scope and excluded_file_count. Pass --include-peripheral to scan the full repo.

Try it in 3 steps

① Scan your server in one command

pip install mcp-blast-radius==0.2.5
mcp-blast-radius-gate --gate-mode advisory --target-dir /path/to/your-mcp-server

Point --target-dir at your shipping package root (e.g. src/). Default scope excludes tests, docs, and scripts.

② Read the JSON

FieldWhat it means
gate_passScan finished (advisory = report either way; blocking = exit 1 on divergences)
blocking_reasonsLines starting with DIVERGENCE: = declared vs. observed mismatch (if you ship a manifest)
blast_radiusStatic capability surface (network, subprocess, env, filesystem)
confidence labelsdeclared / observed-static / cannot-determine — static only, upper bounds

Undeclared capability is usually drift, not malice. Treat network/subprocess counts as upper bounds, not confirmed traffic.

③ Apply for an audit badge (optional, opt-in)

Ran a clean scan and want a signed README badge? Open a badge application — paste your command and JSON. Free, 90-day attestation, no phone-home. Criteria: BADGE_CRITERIA.md.

To verify any published attestation independently: pip install cryptography, then run packaging/scripts/verify_attestation.py (accepts local paths or HTTPS URLs). See BADGE_CRITERIA.md §Verify.


Machine-readable metadata

Example walkthrough

git clone --depth 1 https://github.com/oraios/serena.git /tmp/serena
mcp-blast-radius-gate --gate-mode advisory --target-dir /tmp/serena

Inspect blast_radius and any DIVERGENCE: lines in blocking_reasons.

Report a scan question

Open a GitHub issue with your JSON output (structured template loads automatically).

30-second scan

pip install mcp-blast-radius
mcp-blast-radius-gate --gate-mode blocking --target-dir /path/to/mcp-server

pipx run mcp-blast-radius starts the MCP stdio server (for Claude Desktop / Cursor). For CLI scanning, use mcp-blast-radius-gate as above.

  • Red (blocking): divergence detected — code touches paths or capabilities not declared in manifest.
  • Green: no divergences (or no manifest — blast radius report only, advisory pass).

Install

python3 -m venv .venv
source .venv/bin/activate
pip install .

CLI entry

mcp-blast-radius          # MCP stdio server
mcp-blast-radius-gate     # CI gate (default blocking, exit 1 on fail)

CI blocking gate

mcp-blast-radius-gate --gate-mode blocking --target-dir .
# no divergences → exit 0 / divergences or declaration violations → exit 1

MCP tools

  • aos_compliance_validate — scan one MCP server directory (target_dir required; tool_id optional label)
  • aos_compliance_self_test — wiring smoke test

Default gate_mode=advisory. Use gate_mode=blocking in CI to fail on divergences.

What is extracted

LayerScopeConfidence
Dependenciesrequirements.txt, pyproject.toml, package.jsondeclared
Python ASTimports, file I/O, network, env, subprocess; MCP tool attributionobserved-static / cannot-determine
Divergencemanifest permitted_output_paths / oracle_paths vs observed accessblocking when mismatch

Limitations: Static analysis only. Dynamic imports, getattr/eval, obfuscation, and native extensions may hide capabilities. We do not claim complete coverage — every finding includes a confidence label.

Environment

VariablePurpose
AOS_VALIDATOR_TARGET_DIRDefault scan root when target_dir is omitted
AOS_VALIDATOR_MCP_LOGJSONL path for local tool call log (never sent externally)
AOS_VALIDATOR_CALLERCaller label (ci, smoke_self_call, etc.)

Example

aos_compliance_validate target_dir=/path/to/my-mcp-server gate_mode=blocking

License

MIT

Reviews

No reviews yet

Be the first to review this server!

Blast Radius MCP Server - Static blast-radius audit for MCP servers before agent | MCP Marketplace