Server data from the Official MCP Registry
Audit Make.com blueprints before importing: hardcoded secrets, dangling refs, risky settings.
About
Audit Make.com blueprints before importing: hardcoded secrets, dangling refs, risky settings.
Security Report
A well-designed MCP server for auditing Make.com blueprints with strong security practices. The codebase is clean with proper input validation, careful secret masking to prevent token leakage, and appropriate file-based permissions. Minor code quality findings (broad exception handling, limited input validation on numeric arguments) do not significantly impact the security posture. Permissions align well with the stated purpose of analyzing local blueprint files. Supply chain analysis found 2 known vulnerabilities in dependencies (2 critical, 0 high severity). Package verification found 1 issue.
7 files analyzed · 6 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-arose26-make-audit-mcp": {
"args": [
"-y",
"make-audit-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
make-audit-mcp
An MCP server that audits Make.com (Integromat) scenario blueprints before you import them. Blueprints are shared everywhere — template galleries, forums, "1000 automation" bundles — and importing one means importing its webhooks, HTTP calls, and whatever credential-shaped strings the author left inside.
- "What's in this blueprint?" — modules, apps, trigger, routers, error handling, scenario settings
- "Is it safe to import?" — hardcoded tokens (masked in output), plain-
http://calls, dangling module references, unfiltered router routes, missing error handling, log-retention settings - "What feeds module 5?" — mapping-reference tracing in both directions
Make's official MCP runs your scenarios; this one reviews the files before they become scenarios. Local files only.
Quick start
Claude Code
claude mcp add make-audit -- npx -y make-audit-mcp
Claude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"make-audit": {
"command": "npx",
"args": ["-y", "make-audit-mcp"]
}
}
}
Then: "Audit C:\Downloads\lead-intake.blueprint.json before I import it."
Tools
| Tool | What it does |
|---|---|
inspect_blueprint | Scenario overview: modules, apps, trigger, routers, error handlers, settings |
trace_module | One module in detail — parameters/mappings (secrets masked), references out and in |
audit_blueprint | Findings report: errors / warnings / info |
What the auditor checks
- Credential-shaped literals in parameters or mappings (
api_key,token,Authorization,Bearer …) — connections are stripped on export, so any literal secret is exactly what shouldn't be in a shared file. Values are masked (supe… (18 chars)) everywhere, including in findings — the auditor never amplifies a leaked token into the model's context. - Dangling references — mappings like
{{99.output}}pointing at modules that don't exist (common after hand-editing or merging blueprints). The extractor understands Make's expression syntax:{{formatDate(2.date; "X")}}references module 2, while{{parseNumber(3.14)}}references nothing. - Plain-
http://URLs, webhook triggers (anyone with the URL can invoke), routers where no route is filtered, disabled-but-present modules, no error handlers with DLQ off,confidential=falselog retention.
Known limitation: execution-order validation across router branches is not attempted — reference checks are existence-only.
Development
npm install
npm test # offline tests — synthetic blueprints built in-suite
npm run build # tsc → dist/
node scripts/smoke.mjs # end-to-end: generates a blueprint, drives the server over stdio
Architecture: src/blueprint.ts (recursive module walk, reference extraction, secret masking) and src/audit.ts (checks) are pure logic; src/index.ts is the MCP wiring. Zero runtime deps beyond the MCP SDK.
Not affiliated with or endorsed by Make / Celonis.
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
