Back to Discover

mcp-customs

connector

mcpcustoms

Inspect an MCP server for common security risks before you install it. Offline, zero telemetry.

View on GitHub
0 starsSynced Aug 3, 2026

Install to Claude Code

/plugin marketplace add mcpcustoms/mcp-customs

README

mcp-customs

Inspect an MCP server for common security risks before you install it. Runs fully offline. No telemetry, no cloud upload, no account.

npx mcp-customs scan ./some-mcp-server
──────────────────────────────────────────────────────
MCP-CUSTOMS INSPECTION REPORT
──────────────────────────────────────────────────────
target        ./some-mcp-server
files scanned 14
score         62 / 100
stamp         [ REVIEW ]
──────────────────────────────────────────────────────
[HIGH] MCP002 — Unsanitized file path (possible path traversal)
  server.js:41  return fs.readFileSync(userPath, 'utf8');
  fix: Resolve the path against an allowed base directory ...

Why

Developers install MCP servers the way they used to install npm packages — quickly, trusting the name, and moving on. An MCP server can read your files, call your APIs, and execute commands on your behalf. Almost nobody checks what it can actually do before connecting it to their agent.

mcp-customs is the "audit before install" step, run locally, in seconds.

What it checks (v0.1)

RuleSeverityWhat it looks for
MCP001criticalShell command execution with unsanitized interpolation
MCP002highFile reads/writes without a path-traversal guard
MCP003criticaleval() / dynamic code execution
MCP004highHardcoded API keys / credentials
MCP005criticalTool descriptions containing hidden-instruction language (prompt injection via the tool's own metadata)
MCP006mediumOutbound network calls combined with environment-variable reads (possible exfiltration)
MCP007lowNo permissions/scopes declared in the manifest

These are heuristic, regex-based checks — fast and fully auditable in one sitting, not a dataflow analysis. They will produce false positives and will miss things a deeper analysis would catch. Treat a CLEARED stamp as "nothing obvious," not "verified safe."

CI usage

# .github/workflows/mcp-customs.yml
- run: npx mcp-customs scan . --sarif results.sarif --fail-on high
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: results.sarif

Get a badge for your README

npx mcp-customs scan . --badge --name your-server-name

Roadmap

  • Publish scan results to a public registry (mcp-customs.dev) with searchable trust scores
  • Dynamic/sandboxed analysis (catch what static checks miss)
  • Python-specific AST checks (current Python rules are regex-only)
  • Community flagging / verification on registry entries

License

Apache-2.0. No open-core trap — this CLI stays free either way. If a hosted registry/dashboard ships later, that's a separate paid product; this tool's local scanning will never require it.

Rendered live from mcpcustoms/mcp-customs's GitHub README — not stored, always reflects the source repo.

1 Install Method

NameDescriptionCategorySource
npm packageInstall via npm (stdio transport)mcp-servermcp-customs

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.