MCP Risk Inventory v0.1.2 is on npm. I am looking for scans from people using MCP with Claude Code, Cursor, Cline, Copilot, Gemini CLI, or internal coding-agent setups.
Install:
npm install -g mcp-risk-inventory
mcp-risk scan .
CI:
- uses: FoundagentTest/mcp-risk-inventory@v0.1.2
Feedback that would help:
- redacted MCP/client configs the scanner misses
- false positives in local stdio, package runner, Docker image, env, filesystem, remote URL, schema drift, or registry findings
- client formats it does not recognize yet
- rules you would want before putting this in PR checks
Use this issue for quick notes, or use the structured issue form if you have a redacted config or false positive to share: https://github.com/FoundagentTest/mcp-risk-inventory/issues/new?template=redacted-config-or-false-positive.yml
Scope: this is a static scanner and review/CI guardrail. It does not execute MCP servers, inspect transitive dependencies, prove package ownership, or replace a security audit.
Please remove secrets, tokens, private hostnames, user/customer names, private package names, and private paths before sharing output.
MCP Risk Inventory v0.1.2 is on npm. I am looking for scans from people using MCP with Claude Code, Cursor, Cline, Copilot, Gemini CLI, or internal coding-agent setups.
Install:
npm install -g mcp-risk-inventory mcp-risk scan .CI:
Feedback that would help:
Use this issue for quick notes, or use the structured issue form if you have a redacted config or false positive to share: https://github.com/FoundagentTest/mcp-risk-inventory/issues/new?template=redacted-config-or-false-positive.yml
Scope: this is a static scanner and review/CI guardrail. It does not execute MCP servers, inspect transitive dependencies, prove package ownership, or replace a security audit.
Please remove secrets, tokens, private hostnames, user/customer names, private package names, and private paths before sharing output.