TC Techclick MCP Security Auditor

MCP config and tool manifest review

Find risky MCP commands, scopes, secrets, and poisoned tool descriptions before an agent uses them.

Paste a client config, server manifest, or tool schema. The audit runs as static analysis only: no command execution, no MCP connection, and redacted evidence in the report.

-- score
Checks
SSRF, token passthrough, OAuth, command execution
Output
Prioritized findings, fixes, copyable report
Mode
Paste-only static review

Input

MCP config or manifest

Findings

Prioritized review queue

Audit output appears here with evidence and remediation steps.

What this checks

  • Shell/interpreter execution paths, package runners, and unpinned dependencies.
  • Secret-looking env vars, pasted tokens, broad filesystem paths, and runtime privilege flags.
  • SSRF-prone metadata/internal URLs, wildcard redirects, broad OAuth scopes, and token passthrough language.
  • Tool-description poisoning and risky schemas for path, URL, SQL, regex, or command parameters.

Related Techclick practice