Skip to content

MCP Permission Auditor

Audit an MCP server config for risky capabilities, dangerous combinations such as file read plus network, risk scores and least-privilege fixes.

MCP Permission Auditor

Audit complete: 6 servers, risk 60 of 100, 4 dangerous combinations

Audit dashboard

Servers

6

Capabilities

12

Risk score

60/100

Dangerous combos

4

Audited 6 MCP servers. Overall risk: 60/100. 5 findings identified. 4 dangerous cross-server capability combinations detected.

Dangerous capability combinations

critical

Data exfiltration: can read local files and send them over the network

Servers: filesystem, github, puppeteer, brave-search, custom-deploy

critical

Remote code injection: can download and write malicious files

Servers: filesystem, github, puppeteer, brave-search, custom-deploy

critical

Database exfiltration: can read DB contents and transmit externally

Servers: github, postgres, puppeteer, brave-search, custom-deploy

critical

Remote database manipulation: can receive instructions to modify data

Servers: github, postgres, puppeteer, brave-search, custom-deploy

filesystem

low19/100

npx -y @modelcontextprotocol/server-filesystem /

Package: @modelcontextprotocol/server-filesystemPaths: /Env: HOME

Capabilities

filesystem read3filesystem write8

Findings

high
Overly broad path scope: /

Root-level path scope grants access to the entire filesystem. Restrict to specific project directories.

Recommendations

  • [Recommended]Narrow path scope to specific project directories instead of root-level access.

github

medium34/100

npx -y @modelcontextprotocol/server-github

Package: @modelcontextprotocol/server-githubEnv: GITHUB_PERSONAL_ACCESS_TOKEN

Capabilities

network6code read3code write7issue management3

Findings

critical
Hardcoded credential detected: GITHUB_PERSONAL_ACCESS_TOKEN

The value of GITHUB_PERSONAL_ACCESS_TOKEN appears to be a real credential (ghp_abc1...). Use a secrets manager or environment variable reference instead.

Recommendations

  • [Required]Use a secrets manager or env variable reference (e.g., ${ENV_VAR}) instead of hardcoding credentials in the config file.
  • [Optional]Consider restricting outbound network access to specific domains/IPs if possible.

postgres

low11/100

npx -y @modelcontextprotocol/server-postgres postgresql://admin:password@localhost:5432/mydb

Package: @modelcontextprotocol/server-postgres

Capabilities

database read4database write7

Recommendations

  • [Recommended]Consider using a read-only database user if write access is not required.

puppeteer

low14/100

npx -y @modelcontextprotocol/server-puppeteer

Package: @modelcontextprotocol/server-puppeteer

Capabilities

network6browser5screenshot3

Recommendations

  • [Optional]Consider restricting outbound network access to specific domains/IPs if possible.

brave-search

low16/100

npx -y @modelcontextprotocol/server-brave-search

Package: @modelcontextprotocol/server-brave-searchEnv: BRAVE_API_KEY

Capabilities

network6search2

Findings

high
Potential credential in env: BRAVE_API_KEY

The key name "BRAVE_API_KEY" suggests a credential. Avoid hardcoding secrets in configuration files.

Recommendations

  • [Required]Use a secrets manager or env variable reference (e.g., ${ENV_VAR}) instead of hardcoding credentials in the config file.

custom-deploy

medium28/100

node /opt/mcp-servers/deploy-server.js --target production

Package: /opt/mcp-servers/deploy-server.jsPaths: /opt/mcp-servers/deploy-server.jsEnv: AWS_SECRET_ACCESS_KEY

Capabilities

cloud deploy7network6

Findings

critical
Hardcoded credential detected: AWS_SECRET_ACCESS_KEY

The value of AWS_SECRET_ACCESS_KEY appears to be a real credential (AKIA1234...). Use a secrets manager or environment variable reference instead.

medium
Unrecognized MCP server

"/opt/mcp-servers/deploy-server.js" is not in the known server database. Capabilities were inferred from naming heuristics. Verify manually.

Recommendations

  • [Required]Use a secrets manager or env variable reference (e.g., ${ENV_VAR}) instead of hardcoding credentials in the config file.
  • [Optional]Consider restricting outbound network access to specific domains/IPs if possible.
  • [Recommended]Audit the source code of this MCP server before granting access. Unknown servers may have undocumented capabilities.

Updated . Provided as is. Check the output before you rely on it in production.

How to use MCP Permission Auditor

  1. 1

    Paste your MCP config

    Copy your MCP server configuration JSON (from Claude Desktop, Cursor, or Windsurf settings) and paste it into the input area. Click Load Sample to see an example.

  2. 2

    Review per-server analysis

    Each configured server gets an analysis card showing detected capabilities (filesystem, network, database, code execution), risk score, and specific findings.

  3. 3

    Check for dangerous combinations

    The tool flags dangerous capability combinations — like filesystem plus network access (exfiltration risk) — and credentials exposed in environment variables or arguments.

  4. 4

    Apply recommendations

    Follow the least-privilege suggestions to tighten permissions: scope file paths, move credentials to secure storage, and remove unnecessary server capabilities.

Questions and answers

What is MCP Permission Auditor?
MCP servers give an AI client capabilities such as file access, shell commands or network calls, all declared in an mcpServers config. This auditor classifies each server's capabilities from a list of known servers or by heuristics, scores its risk, flags dangerous combinations and recommends least-privilege changes.
Which MCP config formats are supported?
Claude Desktop, Cursor, and Windsurf JSON config formats. The tool recognizes 50+ well-known MCP servers and uses heuristics for unknown servers.
Does it send my MCP configuration to a server?
No. All analysis happens in your browser. Your MCP configurations — which may contain API tokens — never leave your device.
What are dangerous capability combinations?
For example, a server with both filesystem access and network access creates an exfiltration risk — it could read files and send them externally. The tool detects these combinations and flags them as critical findings.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/mcp-permission-auditor/

For automation planning, fetch the canonical contract at /api/tool/mcp-permission-auditor.json.