MarketNow Registry / Security / @cruxet/mcp-audit

@cruxet/mcp-audit

Local, zero-setup security linter for your MCP client configs. Catches command injection, hardcoded secrets, insecure transports, and known CVEs across Cursor, Claude, Windsurf, VSCode, Continue, Code

MarketNow trust score 72/100 Security v0.2.0 by emrnel
Trust score
72/100
Install risk
Runs registry code
Downloads / week
100
Source
npm-registry
Indexed
2026-09-10

Install

$ npx -y @cruxet/mcp-audit

Installing via npx/uvx/npm install executes arbitrary code from the public registry on your machine. This is the install-risk semantic of the MarketNow catalog — verify the publisher before running it.

Adoption evidence: 100 weekly registry downloads.

How MarketNow scored this

Sentinel Index Heuristics — a security-first estimate from public signals:

Heuristic, not a guarantee. For verified agent credentials and revocation, see the MarketNow Trust API.

What is @cruxet/mcp-audit?

Local, zero-setup security linter for your MCP client configs. Catches command injection, hardcoded secrets, insecure transports, and known CVEs across Cursor, Claude, Windsurf, VSCode, Continue, Code Indexed by MarketNow with trust 72/100 (Runs registry code).

How do I install it?

Run $ npx -y @cruxet/mcp-audit Installing via npx/uvx/npm install executes arbitrary code from the public registry on your machine. This is the install-risk semantic of the MarketNow catalog — verify the publisher before running it.

What does the trust score mean?

Security-first heuristic over public signals (age, adoption, typosquat distance, injection markers). It is not a popularity ranking and not a guarantee of safety. @cruxet/mcp-audit scores 72/100.