Skip to content

v0.1.2 feedback: npm install, redacted configs, false positives #1

Description

@FoundagentTest

MCP Risk Inventory v0.1.2 is on npm. I am looking for scans from people using MCP with Claude Code, Cursor, Cline, Copilot, Gemini CLI, or internal coding-agent setups.

Install:

npm install -g mcp-risk-inventory
mcp-risk scan .

CI:

- uses: FoundagentTest/mcp-risk-inventory@v0.1.2

Feedback that would help:

  • redacted MCP/client configs the scanner misses
  • false positives in local stdio, package runner, Docker image, env, filesystem, remote URL, schema drift, or registry findings
  • client formats it does not recognize yet
  • rules you would want before putting this in PR checks

Use this issue for quick notes, or use the structured issue form if you have a redacted config or false positive to share: https://github.com/FoundagentTest/mcp-risk-inventory/issues/new?template=redacted-config-or-false-positive.yml

Scope: this is a static scanner and review/CI guardrail. It does not execute MCP servers, inspect transitive dependencies, prove package ownership, or replace a security audit.

Please remove secrets, tokens, private hostnames, user/customer names, private package names, and private paths before sharing output.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    config-coverageMCP client config format coveragefeedbackUser feedback, fixtures, and false positives

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions