mcp-tool-auditor
PulseGate's liveness check found it on 14 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 12 Jul 2026. How this is checked
mcp-tool-auditor is an open-source command-line tool designed for security researchers to scan and pentest MCP servers. It provides both defensive scanning and offensive pentesting capabilities, mapping to the OWASP MCP Top 10. The tool helps identify and mitigate security vulnerabilities in AI and LLM-related infrastructures.
Inferred · not functionally tested
Overview
6 featuresPurpose: Detecting and mitigating security vulnerabilities in MCP servers through automated scanning and pentesting.
Inferred · not functionally tested
Audience: security researchers
Inferred · not functionally tested
Functions: Unknown
Interfaces: API: unknown · MCP: indicated (inferred, not tested) · CLI: indicated (inferred, not tested) · Self-hosting: unknown
Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org · github.com. These links do not verify the individual claims.
mcp-tool-auditor sits in PulseGate's Penetration testing & red teaming category. Inferred · not functionally tested: It focuses on detecting and mitigating security vulnerabilities in MCP servers through automated scanning and pentesting. Inferred · not functionally tested: It is built as an open-source project for security researchers. Basis unknown · not verified: The project is open source (MIT). Basis unknown · not verified: It ships for the command line.
Behind mcp-tool-auditor is Perparim Mjeku, and it first shipped in 2026. Development happens publicly on GitHub with 78 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include defensive scanning, offensive pentesting, and OWASP MCP Top 10 mapping. Basis unknown · not verified: Catalogued interfaces include an MCP server.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- Defensive scanning
- Offensive pentesting
- OWASP MCP Top 10 mapping
- CLI interface
- Poisoning detection
- Security reporting
Topics: Inferred · not functionally tested
Built with & integrations
Trust & compliance
Indexing history
1What PulseGate has recorded for this listing
Frequently asked questions about mcp-tool-auditor
- What is mcp-tool-auditor?
- Inferred · not functionally tested: Mcp-tool-auditor focuses on detecting and mitigating security vulnerabilities in MCP servers through automated scanning and pentesting. It is catalogued under Penetration testing & red teaming on PulseGate.
- Who should use mcp-tool-auditor?
- Inferred · not functionally tested: mcp-tool-auditor is an open-source project built for security researchers.
- Is mcp-tool-auditor free?
- Basis unknown · not verified: Yes — mcp-tool-auditor is open source under the MIT license and free to use.
- What platforms does mcp-tool-auditor run on?
- Basis unknown · not verified: mcp-tool-auditor runs on the command line.
- Is mcp-tool-auditor still active?
- PulseGate's liveness check found it on 14 Sep 2026. Its GitHub repository shows 78 commits in the last 90 days.
- What are alternatives to mcp-tool-auditor?
- Similar projects tracked by PulseGate include mcp-audits, mcp-config-audit, and mcp-audit-scanner.mcp-auditsmcp-config-auditmcp-audit-scanner
- Who develops mcp-tool-auditor?
- mcp-tool-auditor is developed by Perparim Mjeku.
- How long has mcp-tool-auditor been around?
- mcp-tool-auditor first shipped in 2026.
Similar projects
Closest matches by what these projects do