https://github.com/qianniuspace/mcp-security-audit
A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.
https://github.com/qianniuspace/mcp-security-audit
audit model-context-protocol npm security
Last synced: about 1 month ago
JSON representation
A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.
- Host: GitHub
- URL: https://github.com/qianniuspace/mcp-security-audit
- Owner: qianniuspace
- License: mit
- Created: 2025-02-20T16:12:01.000Z (over 1 year ago)
- Default Branch: main
- Last Pushed: 2025-07-18T09:03:21.000Z (about 1 year ago)
- Last Synced: 2025-10-05T04:39:19.200Z (about 1 year ago)
- Topics: audit, model-context-protocol, npm, security
- Language: TypeScript
- Homepage: https://mcpdirs.com/
- Size: 1.87 MB
- Stars: 46
- Watchers: 1
- Forks: 8
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- Changelog: CHANGELOG.md
- License: LICENSE
- Code of conduct: CODE_OF_CONDUCT.md
Awesome Lists containing this project
- awesome-mcp - qianniuspace/mcp-security-audit
- awesome-mcp-servers - qianniuspace/mcp-security-audit - A powerful MCP server for auditing npm package dependencies for security vulnerabilities, integrating remote npm registry for real-time checks. ([Read more](/details/qianniuspacemcp-security-audit.md)) `mcp` `security` `npm` `vulnerability` (Security & Attestation MCP Servers)
- awesome-devops-mcp-servers - qianniuspace/mcp-security-audit - A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks. (Cloud Infrastructure / 🔒 Security)
- awesome-mcp-zh - qianniuspace/mcp-security-audit
- awesome-mcp-servers - Security Audit MCP Server - time security checks. (Legend / 🔒 <a name="security"></a>Security)
- awesome-mcp-servers - **mcp-security-audit** - A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks. `typescript` `audit` `model-context-protocol` `npm` `security` `npm install qianniuspace/mcp-security-audit` (🔐 Authentication)
- awesome-mcp-servers - Security Audit MCP Server
- metorial-index - Mcp Security Audit - Audits npm package dependencies for security vulnerabilities using remote npm registry integration for real-time checks. (Security)
- awesome-mcp - Security Audit MCP Server - time security checks. (MCP Servers / 🔒 Security)
- toolsdk-mcp-registry - ✅ mcp-security-audit - audit-report and npm-registry-fetch to analyze and report potential vulnerabilities in Node.js project dependencies, offering actionable security insights for development teams. (1 tools) (node) (Security / How to Submit)
- awesome-claude-code-security - MCP Security Audit (npm) - Audits npm dependencies in MCP servers for known vulnerabilities via registry. (🔌 MCP Security / Scanners and Auditors)
- awesome-devops-mcp - qianniuspace/mcp-security-audit - Audit npm package dependencies for security vulnerabilities (🧩 Miscellaneous)
- awesome-mcp-servers - Security Audit MCP Server
- awesome-mcp-security - qianniuspace/mcp-security-audit - A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks. (Cloud Infrastructure / 🔒 Security)
- awesome-mcp-servers - MCP Security Auditor - A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks. (Table of Contents / Security)
- awesome-mcp-security - mcp-security-audit - security-audit) | (🔒 Security (50 servers))
README
# Security Audit Tool
[](https://smithery.ai/server/@qianniuspace/mcp-security-audit)
[](https://www.npmjs.com/package/mcp-security-audit)
[](https://opensource.org/licenses/MIT)
A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.
## Features
- 🔍 Real-time security vulnerability scanning
- 🚀 Remote npm registry integration
- 📊 Detailed vulnerability reports with severity levels
- 🛡️ Support for multiple severity levels (critical, high, moderate, low)
- 📦 Compatible with npm/pnpm/yarn package managers
- 🔄 Automatic fix recommendations
- 📋 CVSS scoring and CVE references
### Installing via Smithery
To install Security Audit Tool for Claude Desktop automatically via [Smithery](https://smithery.ai/server/@qianniuspace/mcp-security-audit):
```bash
npx -y @smithery/cli install @qianniuspace/mcp-security-audit --client claude
```
### MCP Integration
#### Option 1: Using NPX (Recommended)
1. Add MCP configuration to Cline /Cursor:
```json
{
"mcpServers": {
"mcp-security-audit": {
"command": "npx",
"args": ["-y", "mcp-security-audit"]
}
}
}
```
#### Option 2: Download Source Code and Configure Manually
1. Clone the repository:
```bash
git clone https://github.com/qianniuspace/mcp-security-audit.git
cd mcp-security-audit
```
2. Install dependencies and build:
```bash
npm install
npm run build
```
3. Add MCP configuration to Cline /Cursor :
```json
{
"mcpServers": {
"mcp-security-audit": {
"command": "npx",
"args": ["-y", "/path/to/mcp-security-audit/build/index.js"]
}
}
}
```
## Configuration Screenshots
### Cursor Configuration

### Cline Configuration

## API Response Format
The tool provides detailed vulnerability information including severity levels, fix recommendations, CVSS scores, and CVE references.
### Response Examples
#### 1. When Vulnerabilities Found (Severity-response.json)
```json
{
"content": [{
"vulnerability": {
"packageName": "lodash",
"version": "4.17.15",
"severity": "high",
"description": "Prototype Pollution in lodash",
"cve": "CVE-2020-8203",
"githubAdvisoryId": "GHSA-p6mc-m468-83gw",
"recommendation": "Upgrade to version 4.17.19 or later",
"fixAvailable": true,
"fixedVersion": "4.17.19",
"cvss": {
"score": 7.4,
"vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cwe": ["CWE-1321"],
"url": "https://github.com/advisories/GHSA-p6mc-m468-83gw"
},
"metadata": {
"timestamp": "2024-04-23T10:00:00.000Z",
"packageManager": "npm"
}
}]
}
```
#### 2. When No Vulnerabilities Found (no-Severity-response.json)
```json
{
"content": [{
"vulnerability": null,
"metadata": {
"timestamp": "2024-04-23T10:00:00.000Z",
"packageManager": "npm",
"message": "No known vulnerabilities found"
}
}]
}
```
## Development
For development reference, check the example response files in the `public` directory:
- [Severity-response.json](public/Severity-response.json) : Example response when vulnerabilities are found (transformed from npm audit API response)
- [no-Severity-response.json](public/no-Severity-response.json) : Example response when no vulnerabilities are found (transformed from npm audit API response)
Note: The example responses shown above are transformed from the raw npm audit API responses to provide a more structured format. The original npm audit API responses contain additional metadata and may have a different structure.
## Contributing
Contributions are welcome! Please read our [Contributing Guide](CODE_OF_CONDUCT.md) for details on our code of conduct and the process for submitting pull requests.
## License
This project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.
## Author
ESX (qianniuspace@gmail.com)
## Links
- [GitHub Repository](https://github.com/qianniuspace/mcp-security-audit)
- [Issue Tracker](https://github.com/qianniuspace/mcp-security-audit/issues)
- [Changelog](CHANGELOG.md)
```