Free · open source · no account
How many ungoverned MCP servers are on your laptop right now?
Every MCP server configured in Claude Code, Cursor, or Windsurf can read your files, hold your API keys, and reach the network. Most teams have no idea what's installed. One command tells you — in about 60 seconds.
npx -y @curatedmcp/auditorRuns locally. Exits non-zero if high-risk servers are found — CI-friendly.
Finds every MCP config
Scans the config locations for Claude Code, Claude Desktop, Cursor, Windsurf, and Gemini on your machine.
Flags shadow servers
Each server is checked against the risk-classified CuratedMCP catalog. Anything in no governed catalog is shadow MCP — software with credential access that nobody reviewed.
Grades the machine A–F
Get a shareable, unlisted report URL — the artifact you paste in Slack or forward to your security lead.
What leaves your machine: almost nothing.
The scan runs entirely locally and prints its findings in your terminal. Generating a shareable web report is optional and asks first — and uploads only server names, which IDE they came from, and risk flags. Commands, arguments, env values, secrets, and file paths never leave your machine. The CLI is MIT-licensed open source, so you can check.
What the report looks like
High risk found
11 servers across Claude Code, Cursor — 4 shadow, 1 high-risk
Found something? Fix this machine.
The Hub governs your machine: one MCP endpoint for every AI client, every server risk-checked against the catalog, a policy guard in front of risky tool calls.
This scan covers one machine.
The Control Plane governs your fleet: this scan on every developer laptop, an org allowlist, and the audit trail security asks for.
Larger org? See the 60-day deployed-for-you pilot