{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_bspmx35gak7w","handle":"velox-mcp-audit","url":"https://wellknown.network/agents/velox-mcp-audit","links":{"self":"https://wellknown.network/agents/velox-mcp-audit/record.json","html":"https://wellknown.network/agents/velox-mcp-audit","markdown":"https://wellknown.network/agents/velox-mcp-audit/record.md","api":"https://wellknown.network/api/v1/agents/velox-mcp-audit","status":"https://wellknown.network/api/v1/agents/velox-mcp-audit/status","claim":"https://wellknown.network/agents/velox-mcp-audit/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/velox-mcp-audit/claim.json","badge":"https://wellknown.network/agents/velox-mcp-audit/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:velox-mcp-audit","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"velox-mcp-audit","summary":"Security scanner for Model Context Protocol (MCP) servers","description":"# mcp-audit\n\n> Security scanner for Model Context Protocol (MCP) servers.\n\n[![status: early alpha](https://img.shields.io/badge/status-early%20alpha-orange.svg)](https://github.com/veloxlabsio/mcp-audit)\n[![python: 3.10+](https://img.shields.io/badge/python-3.10+-blue.svg)](https://www.python.org/)\n[![license: MIT](https://img.shields.io/badge/license-MIT-green.svg)](LICENSE)\n\n> **Renamed from `mcp-scan` → `mcp-audit` in April 2026** to avoid collision with Snyk's Agent Scan (formerly Invariant Labs' mcp-scan). The old PyPI package `velox-mcp-scan` is deprecated; install `velox-mcp-audit` instead.\n\n**mcp-audit** is an open-source CLI that inspects MCP servers for known security issues. It connects to a server via stdio, fetches its tool/resource/prompt manifest, and runs a battery of checks against the metadata.\n\n> **Early alpha.** Currently ships 6 checks: 2 protocol-level (prompt injection markers, ANSI/control character smuggling) and 4 source-code AST checks (path traversal, shell injection, SSRF sinks, hardcoded secrets). 19 more are planned — see [`docs/checks.md`](docs/checks.md) for the full roadmap. Only stdio transport is implemented; HTTP/SSE is planned.\n\nBuilt by [Velox Labs](https://veloxlabs.dev) — an AI security and platform engineering studio.\n\n---\n\n## What it catches today\n\n**Protocol-level checks** (run against any MCP server, no source access needed):\n\n| Check | Severity | What it detects |\n|---|---|---|\n| **MCPA-001** | Critical | Prompt-injection markers in tool descriptions (imperative verbs, `<system>` tags, exfiltration phrases) |\n| **MCPA-002** | High | ANSI escape sequences, C0 control chars, and zero-width characters hiding payloads in tool descriptions |\n\n**Source-code AST checks** (require `--source <path>` pointing at the server's Python source):\n\n| Check | Severity | What it detects |\n|---|---|---|\n| **MCPA-010** | Critical | Path traversal in file handlers — `open()`/`read_text()` without `is_relative_to()` containment (`resolve()` a…","publisher":{"name":"Velox Labs","url":null},"homepage":"https://veloxlabs.dev","repository":"https://github.com/veloxlabsio/mcp-audit/issues","version":"0.2.0","license":"MIT","protocols":["mcp"],"tags":["agent","audit","llm","mcp","scanner","security"],"pricing":null,"endpoints":[{"url":"pypi:velox-mcp-audit","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi","publisherName":"pypi"}},"derived":{"capabilities":[{"slug":"security.scanning","name":"Security Scanning","confidence":1,"provenance":"declared"},{"slug":"dev.version-control","name":"Version Control","confidence":0.779,"provenance":"derived"},{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":0.768,"provenance":"derived"}],"categories":["dev","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"velox-mcp-audit","registry":"pypi","observedAt":"2026-09-10T15:25:07.483Z","publishedAt":"2026-04-21T07:56:36.277375Z","latestVersion":"0.2.0"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"velox-mcp-audit","url":"https://pypi.org/project/velox-mcp-audit/","firstSeenAt":"2026-09-10T15:23:18.313Z","fetchedAt":"2026-09-10T15:23:18.313Z","normalizedAt":"2026-09-10T15:23:18.313Z"}]},"firstSeenAt":"2026-09-10T15:23:18.313Z","updatedAt":"2026-09-10T15:25:07.483Z"}