mcp-audit
Audit the configured MCP servers (user + project scope) via the Agent Monitor Config Explorer API: transport (stdio vs http), command/args and env variable names, headers, and the source file each definition came from. Reads /api/cc-config/mcp
Install / Use
npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill mcp-auditInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
OperationsSupported Platforms
Our assessment of mcp-audit
mcp-audit scores 85/100 on our quality scale, 486th of 736 Operations skills we index.
Its SKILL.md is 2.7 KB long, well organised into 8 sections and no code examples: a solid amount of guidance for an agent.
With 1,015 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 12 days ago, so mcp-audit is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
mcp-audit compared with similar skills
All 4 of these similar skills score higher than mcp-audit; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| mcp-audit (this skill)by hoangsonww | 85 | 1.0k | 12d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 92.4k | 21d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.9k | today | MCP Server |
Frequently asked questions
- How do I install mcp-audit?
- Run
npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill mcp-audit. The install tabs above show the steps for each supported agent. - Which AI agents does mcp-audit work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is mcp-audit safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is mcp-audit still maintained?
- The repository was last updated 12 days ago, so mcp-audit is actively maintained.
Skill content
View source on GitHubname: mcp-audit description: > Audit the configured MCP servers (user + project scope) via the Agent Monitor Config Explorer API: transport (stdio vs http), command/args and env variable names, headers, and the source file each definition came from. Reads /api/cc-config/mcp. Use when reviewing MCP integrations for hygiene, duplication, or unexpected transports.
MCP Audit
Inventory and audit every Model Context Protocol server the user has
configured — both user-scope and project-scope — read through the Agent Monitor
dashboard at http://localhost:4820.
Input
The user provides: $ARGUMENTS
This may be:
- empty — audit all MCP servers (default).
- a server name fragment — focus on matching servers.
- "stdio" / "http" — restrict to one transport kind.
Data Sources
| Endpoint | Returns |
|----------|---------|
| GET /api/cc-config/mcp | { user:[…], projectScoped:[…] }. Each server: { name, source, kind } where kind is stdio (with command, args, envNames), http (with url, headers), or unknown. source names the file the definition came from (e.g. ~/.claude.json (top-level), ~/.claude.json (projects[<root>]), ~/.claude/settings.json) |
Report Sections
1. Server inventory
List every server from user and projectScoped. For each show name,
source, kind, and the transport detail:
- stdio — the
command, itsargs, and theenvNames(names only — values are not exposed by the API). - http — the
urland theheaderskey names (values not exposed). - unknown — a definition the server could not classify; flag it for review.
2. Scope split & duplication
Separate user-scope from project-scope servers. Flag any name that appears in
both scopes (project may shadow user) and any duplicate definitions across
source files.
3. Hygiene flags
- Unknown transport — servers with
kind: "unknown"(malformed or unsupported definition). - Env reliance — stdio servers with many
envNames; note they depend on environment variables being present at launch. - Remote endpoints — http servers; surface the
urlhost so the user can confirm they trust the remote.
Output
- Section 1 as a table (
Scope | Name | Kind | Transport detail | Source). - Env names and header names listed by name only — never invent or print values (the API does not expose them).
- Cite only fields the API returned — never fabricate servers, commands, or hosts.
- Note: MCP servers are read-only via the Config Explorer (they are written
concurrently by the running CLI); edit their definitions in the source file
named by
source. - If the dashboard is unreachable at
http://localhost:4820, say so and tell the user to start it withnpm startfrom the repo root.
Related Skills
Agent-Reach
92.4kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.9k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
