mcp-security-audit logo

mcp-security-auditA powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

mcp-security-audit is a powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. It integrates with the remote npm registry for real-time security checks. The tool is designed to help developers identify and address potential security issues in their projects. It provides detailed vulnerability reports, including severity levels, fix recommendations, CVSS scores, and CVE references. The tool supports multiple severity levels (critical, high, moderate, low) and is compatible with npm, pnpm, and yarn package managers.

Key features

  • Real-time security vulnerability scanning
  • Remote npm registry integration
  • Detailed vulnerability reports with severity levels
  • Support for multiple severity levels (critical, high, moderate, low)
  • Compatible with npm/pnpm/yarn package managers
  • Automatic fix recommendations

Pricing

Model
Free
Category
MCP Servers
Rating
No reviews yet

Use cases

Security Audit

Perform a security audit on npm package dependencies to identify potential vulnerabilities

Vulnerability Management

Use the tool to manage vulnerabilities in a project, including identifying severity levels and recommended fixes

Pros & Cons

Pros

  • Real-time security vulnerability scanning
  • Detailed vulnerability reports with severity levels
  • Automatic fix recommendations
  • CVSS scoring and CVE references
  • Support for multiple severity levels

Cons

  • Limited to npm package dependencies
  • Requires MCP configuration for integration

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

Are there any limitations to the tool's functionality?

Yes, it is limited to auditing npm package dependencies for security vulnerabilities and requires MCP configuration for integration.

Asked by Ivana Novak · Jan 9, 2026

What information is included in vulnerability reports?

Detailed vulnerability reports include severity levels, fix recommendations, CVSS scores, and CVE references.

Asked by Omar Haddad · Nov 19, 2025

Can it scan for vulnerabilities in real-time?

Yes, it provides real-time security vulnerability scanning with remote npm registry integration.

Asked by Ivo Novotný · Nov 11, 2025

What package managers are supported?

The tool is compatible with npm, pnpm, and yarn package managers.

Asked by Tunde Balogun · Nov 8, 2025

Ask a question

MCP Servers alternatives