~ / rigs / sattyamjjain / agent-audit-kit

sattyamjjain/agent-audit-kit

Static scanner for MCP-connected AI agent pipelines. 387 rules across 14 categories, 14 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.

↗ GitHub ★ 12 apache-2.0 updated 1d ago project Claude Code
share on X
ARCHETYPE
YOLO Cowboy
Permissions? Never heard of 'em. Ships at the speed of `--dangerously-skip-permissions`.
CONTEXT TAX · EVERY TURN
~51.0k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add --transport http analytics http://mcp-analytics.example.com/v1/sse
$ claude mcp add --transport http internal-tools http://192.168.1.50:8080/mcp -H 'X-Custom-Header: YOUR_VALUE'
$ claude mcp add unpinned-fetcher -- npx @modelcontextprotocol/server-filesystem
$ claude mcp add custom-binary -- my-custom-binary --port 3000
$ claude mcp add filesystem-access -- npx @modelcontextprotocol/server-filesystem@1.0.0 /
$ claude mcp add --transport http plaintext-api http://mcp.example.com/api
$ claude mcp add --transport http legacy-sse https://mcp.example.com/sse
$ claude mcp add --transport http token-in-url 'https://mcp.example.com/api<redacted><redacted>'
$ npx degit sattyamjjain/agent-audit-kit/examples/vulnerable-configs/04-hook-exfiltration/.claude ./rig-agent-audit-kit  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add --transport http analytics http://mcp-analytics.example.com/v1/sse
$ claude mcp add --transport http internal-tools http://192.168.1.50:8080/mcp -H 'X-Custom-Header: YOUR_VALUE'
$ claude mcp add unpinned-fetcher -- npx @modelcontextprotocol/server-filesystem
$ claude mcp add custom-binary -- my-custom-binary --port 3000
$ claude mcp add filesystem-access -- npx @modelcontextprotocol/server-filesystem@1.0.0 /
$ claude mcp add --transport http plaintext-api http://mcp.example.com/api
$ claude mcp add --transport http legacy-sse https://mcp.example.com/sse
$ claude mcp add --transport http token-in-url 'https://mcp.example.com/api<redacted><redacted>'

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

MCP servers (15)

serversourceest. tokens
mcp-analytics.example.com · "analytics" remote · remote 2.5k
192.168.1.50 · "internal-tools" remote · remote 2.5k
compromised-server local / custom 2.5k
Filesystem · "unpinned-fetcher" npm 4.2k
my-custom-binary · "custom-binary" binary 2.5k
auth-helper local / custom 2.5k
Filesystem · "filesystem-access" npm 4.2k
ai-assistant
env: ANTHROPIC_API_KEY, DATABASE_URL, OPENAI_API_KEY
local / custom 2.5k
cloud-tools
env: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY
local / custom 2.5k
some-server local / custom 2.5k
malicious-server local / custom 2.5k
mcp.example.com · "plaintext-api" remote · remote 2.5k
tls-disabled
env: NODE_TLS_REJECT_UNAUTHORIZED
local / custom 2.5k
mcp.example.com · "legacy-sse" remote · remote 2.5k
mcp.example.com · "token-in-url" remote · remote 2.5k

Permissions

deny (0)
—
ask (0)
—
allow (5)
*
mcp__*
Bash(*)
Edit(**)
Write(**)

Similar rigs

copied ✓