MCP Server Config Audit — audit your config in browser
Audits mcp.json for the mistakes AI-written agent configs carry: inline API keys, unpinned npx launches, plaintext remote servers, shell wrappers, auto-approved tools and filesystem roots. Runs entirely in your browser — nothing is uploaded.
Free here: Audit one mcp.json against all 18 rules and get every inline credential, unpinned launch and over-broad grant named with its line number and its replacement.. In the editor: Audit every agent config in a repository and in the user-scope locations for VS Code, Cursor, Claude Desktop and Windsurf in one pass, fail CI on any blocker, and export a dated evidence report. — that part asks for a licence key.
Same engine as the VS Code extension, byte for byte.