MCP Permission Auditor
Audit an MCP server config for risky capabilities, dangerous combinations such as file read plus network, risk scores and least-privilege fixes.
MCP Permission Auditor
Audit complete: 6 servers, risk 60 of 100, 4 dangerous combinations
Audit dashboard
Servers
6
Capabilities
12
Risk score
60/100
Dangerous combos
4
Audited 6 MCP servers. Overall risk: 60/100. 5 findings identified. 4 dangerous cross-server capability combinations detected.
Dangerous capability combinations
Data exfiltration: can read local files and send them over the network
Servers: filesystem, github, puppeteer, brave-search, custom-deploy
Remote code injection: can download and write malicious files
Servers: filesystem, github, puppeteer, brave-search, custom-deploy
Database exfiltration: can read DB contents and transmit externally
Servers: github, postgres, puppeteer, brave-search, custom-deploy
Remote database manipulation: can receive instructions to modify data
Servers: github, postgres, puppeteer, brave-search, custom-deploy
filesystem
low19/100npx -y @modelcontextprotocol/server-filesystem /
Capabilities
Findings
Root-level path scope grants access to the entire filesystem. Restrict to specific project directories.
Recommendations
- [Recommended]Narrow path scope to specific project directories instead of root-level access.
github
medium34/100npx -y @modelcontextprotocol/server-github
Capabilities
Findings
The value of GITHUB_PERSONAL_ACCESS_TOKEN appears to be a real credential (ghp_abc1...). Use a secrets manager or environment variable reference instead.
Recommendations
- [Required]Use a secrets manager or env variable reference (e.g., ${ENV_VAR}) instead of hardcoding credentials in the config file.
- [Optional]Consider restricting outbound network access to specific domains/IPs if possible.
postgres
low11/100npx -y @modelcontextprotocol/server-postgres postgresql://admin:password@localhost:5432/mydb
Capabilities
Recommendations
- [Recommended]Consider using a read-only database user if write access is not required.
puppeteer
low14/100npx -y @modelcontextprotocol/server-puppeteer
Capabilities
Recommendations
- [Optional]Consider restricting outbound network access to specific domains/IPs if possible.
brave-search
low16/100npx -y @modelcontextprotocol/server-brave-search
Capabilities
Findings
The key name "BRAVE_API_KEY" suggests a credential. Avoid hardcoding secrets in configuration files.
Recommendations
- [Required]Use a secrets manager or env variable reference (e.g., ${ENV_VAR}) instead of hardcoding credentials in the config file.
custom-deploy
medium28/100node /opt/mcp-servers/deploy-server.js --target production
Capabilities
Findings
The value of AWS_SECRET_ACCESS_KEY appears to be a real credential (AKIA1234...). Use a secrets manager or environment variable reference instead.
"/opt/mcp-servers/deploy-server.js" is not in the known server database. Capabilities were inferred from naming heuristics. Verify manually.
Recommendations
- [Required]Use a secrets manager or env variable reference (e.g., ${ENV_VAR}) instead of hardcoding credentials in the config file.
- [Optional]Consider restricting outbound network access to specific domains/IPs if possible.
- [Recommended]Audit the source code of this MCP server before granting access. Unknown servers may have undocumented capabilities.
Updated . Provided as is. Check the output before you rely on it in production.
How to use MCP Permission Auditor
- 1
Paste your MCP config
Copy your MCP server configuration JSON (from Claude Desktop, Cursor, or Windsurf settings) and paste it into the input area. Click Load Sample to see an example.
- 2
Review per-server analysis
Each configured server gets an analysis card showing detected capabilities (filesystem, network, database, code execution), risk score, and specific findings.
- 3
Check for dangerous combinations
The tool flags dangerous capability combinations — like filesystem plus network access (exfiltration risk) — and credentials exposed in environment variables or arguments.
- 4
Apply recommendations
Follow the least-privilege suggestions to tighten permissions: scope file paths, move credentials to secure storage, and remove unnecessary server capabilities.
Questions and answers
What is MCP Permission Auditor?
Which MCP config formats are supported?
Does it send my MCP configuration to a server?
What are dangerous capability combinations?
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/mcp-permission-auditor/
For automation planning, fetch the canonical contract at /api/tool/mcp-permission-auditor.json.