Skip to content

v0.1.2 feedback: npm install, redacted configs, false positives #1

Description

@FoundagentTest

MCP Risk Inventory v0.1.2 is on npm. I am looking for scans from people using MCP with Claude Code, Cursor, Cline, Copilot, Gemini CLI, or internal coding-agent setups.

Install:

npm install -g mcp-risk-inventory
mcp-risk scan .

CI:

- uses: FoundagentTest/mcp-risk-inventory@v0.1.2

Feedback that would help:

  • redacted MCP/client configs the scanner misses
  • false positives in local stdio, package runner, Docker image, env, filesystem, remote URL, schema drift, or registry findings
  • client formats it does not recognize yet
  • rules you would want before putting this in PR checks

Use this issue for quick notes, or use the structured issue form if you have a redacted config or false positive to share: https://github.com/FoundagentTest/mcp-risk-inventory/issues/new?template=redacted-config-or-false-positive.yml

Scope: this is a static scanner and review/CI guardrail. It does not execute MCP servers, inspect transitive dependencies, prove package ownership, or replace a security audit.

Please remove secrets, tokens, private hostnames, user/customer names, private package names, and private paths before sharing output.

Metadata

Metadata

Assignees

No one assigned

    Labels

    config-coverageMCP client config format coveragefeedbackUser feedback, fixtures, and false positives

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions