Back to Browse

Security Auditor MCP Server

by craterz
SecurityModerate6.2Local
$2.00

Your AI's Senior Security Engineer. Instantly audits local code for OWASP risks and leaked secrets.

About

**What it does:** Security Auditor Pro upgrades your local AI agent (Claude Desktop, Cursor, Antigravity) into a Senior DevSecOps Engineer. It gives your AI the native ability to deeply scan your local codebase and hunt for severe security risks—like hardcoded API keys, dangerous arbitrary code execution (e.g., eval()), and critical OWASP Top 10 vulnerabilities (like SQL injections and XSS).

**How it works:** Built natively on the Model Context Protocol (MCP), it securely exposes the `audit_codebase` tool to your AI. When asked to review a file or an entire directory, the server rapidly scans the raw code for dangerous anti-patterns and leaked secrets, compiling a structured threat report directly into the AI's context window. The AI then explains the vulnerabilities to you and writes the exact patches needed to secure them.

**Who it's for:** This tool is built for developers, agency owners, and security researchers who want to ensure their code is perfectly secure before shipping to production. Instead of paying for an expensive manual security audit, simply ask your AI to *"audit the /src directory"* and instantly secure your application.

Security Report

6.2
Moderate6.2Moderate Risk

This security auditor MCP server has a clear purpose and appropriate permissions for local file scanning, but contains several security concerns that limit its reliability. The main issues are: inadequate input validation allowing directory traversal attacks, overly simplistic pattern-matching for security scanning that produces false positives/negatives, potential sensitive data exposure in error messages, and lack of proper output escaping. While not malicious, these flaws undermine the server's credibility as a security tool and create exploitable attack surfaces. Package verification found 1 issue.

2 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

file_stat

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Install instructions and configuration are available after purchase.

Getting Started

Once installed, try these example prompts and explore these capabilities:

  • 1"Audit my entire /backend directory for security risks"
  • 2"Check this auth.js file for any leaked secrets or dangerous code"
  • 3"Scan the current workspace for OWASP Top 10 vulnerabilities"
  • 4Tool: audit_codebase: Scans a target path for hardcoded secrets and dangerous patterns

Reviews

5.01 rating
5
1
4
0
3
0
2
0
1
0

No written reviews yet. Be the first!

Security Auditor MCP Server - Your AI's Senior Security Engineer. Instantly audits local | MCP Marketplace