~ / rigs / shriramkv / mcp-client-config-audit

shriramkv/mcp-client-config-audit

Audits MCP client configs (Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, goose) for risky server wiring like unpinned packages, leaked secrets, shell wrappers and unsafe containers, and grades each A-F with CI gates.

↗ GitHub ★ 1 MIT updated 13d ago personal setup Codex
share on X
ARCHETYPE
MCP Hoarder
Six or more MCP servers wired in. Every tool, always in context.
CONTEXT TAX · EVERY TURN
~40.6k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem@2025.8.21 ~/projects/agent-demo
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_<redacted>:v0.13.0
$ claude mcp add --transport http remote-crm 'http://crm.internal.example.com/mcp<redacted>' -H 'Authorization: YOUR_VALUE'
$ claude mcp add sandbox -- docker run -i --rm --privileged -v /var/run/docker.sock:/var/run/docker.sock --network host example/sandbox-mcp
$ claude mcp add fetch -e NODE_TLS_REJECT_UNAUTHORIZED=YOUR_NODE_TLS_REJECT_UNAUTHORIZED -- uvx mcp-server-fetch
$ claude mcp add --transport sse search https://search.example.com/sse -H 'X-API-Key: YOUR_VALUE'
$ claude mcp add --transport http experimental wss://ws.example.com/mcp

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem@2025.8.21 ~/projects/agent-demo
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_<redacted>:v0.13.0
$ claude mcp add --transport http remote-crm 'http://crm.internal.example.com/mcp<redacted>' -H 'Authorization: YOUR_VALUE'
$ claude mcp add sandbox -- docker run -i --rm --privileged -v /var/run/docker.sock:/var/run/docker.sock --network host example/sandbox-mcp
$ claude mcp add fetch -e NODE_TLS_REJECT_UNAUTHORIZED=YOUR_NODE_TLS_REJECT_UNAUTHORIZED -- uvx mcp-server-fetch
$ claude mcp add --transport sse search https://search.example.com/sse -H 'X-API-Key: YOUR_VALUE'
$ claude mcp add --transport http experimental wss://ws.example.com/mcp

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

MCP servers (10)

serversourceest. tokens
Filesystem npm 4.2k
GitHub MCP · "github"
env: GITHUB_PERSONAL_ACCESS_TOKEN
docker 18.0k
runner local / custom 2.5k
local-tool local / custom 2.5k
old-server local / custom 2.5k
crm.internal.example.com · "remote-crm" remote · remote 2.5k
example/sandbox-mcp · "sandbox" docker 2.5k
Fetch
env: NODE_TLS_REJECT_UNAUTHORIZED
pypi 450
search.example.com · "search" remote · remote 2.5k
ws.example.com · "experimental" remote · remote 2.5k

Similar rigs

copied ✓