# graygnatconsole/mcp-audit-tool > A pure-Python CLI that statically audits MCP server configs for hardcoded secrets, unpinned packages, command injection, and tool poisoning before an AI agent runs them. - Magnitude: 3.7 out of 10 — Early signal - Stars: 70 total · +0 stars today, ≈ 36 by evening - Star trust: star growth looks organic - Category: Security · Language: Python · License: MIT · Created: 2026-09-26 · Last push: 2026-09-26 - GitHub: https://github.com/graygnatconsole/mcp-audit-tool · Page: https://gitnova.dev/en/r/graygnatconsole/mcp-audit-tool ## Useful for - Scan claude_desktop_config.json and .cursor/mcp.json for leaked API keys and unsafe commands - Add mcp-audit scan --fail-on high to CI to block builds on critical findings - Export a SARIF report and upload it to GitHub Code Scanning for the team ## Why it’s here - 0 stars so far today, about 35 expected by the end of the day. - The spike has held for 2 days in a row — not a one-off blip. - The repository is 1 day old and already has 70 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - Top new repositories this week: #192. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 1 - Issues and pull requests: 0 - Watchers: 0 - Average over the last week: 38 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 1 ## Stars per day, last 8 days (oldest → newest, today is partial) 2026-09-20 … 2026-09-27: 0, 0, 0, 0, 0, 29, 41, 0 ## Spotted in now - Top new repositories this week: #192 ## More in this category 1. **Soniavasseur/Wallet-Risk-Scanner** — 6.2 · Early signal · Security · Python · +0 stars today, ≈ 158 by evening Multi-chain crypto wallet risk scanner for AML/KYT screening: scores addresses 0–100 using sanctions lists, risky contracts and fund tracing across 6 intelligence providers and 15+ blockchains. Full card: https://gitnova.dev/en/r/Soniavasseur/Wallet-Risk-Scanner.md 2. **derv82/wifit3** — 6.0 · Early signal · Security · Python · +0 stars today, ≈ 172 by evening Cross-platform USB Wi-Fi auditor in Python: scans networks, captures WPA handshakes and PMKIDs, attacks WPS and WEP via its own userland drivers without aircrack-ng. Full card: https://gitnova.dev/en/r/derv82/wifit3.md 3. **openbao/openbao** — 5.6 · Breakout · Security · Go · +0 stars today, ≈ 170 by evening OpenBao is an open-source secrets management system for storing, encrypting, and distributing credentials, keys, and certificates, with dynamic secrets and auditing. A community-governed fork of Vault. Full card: https://gitnova.dev/en/r/openbao/openbao.md 4. **Roberto02800/turnstile-token** — 5.1 · Early signal · Security · Python · +0 stars today, ≈ 40 by evening A dependency-free Python client and CLI for obtaining Cloudflare Turnstile tokens via the paid Clearance API: it discovers the sitekey on a page, solves the challenge, and returns the token together with the browser fingerprint it was… Full card: https://gitnova.dev/en/r/Roberto02800/turnstile-token.md 5. **newliver666/apk-reverse** — 5.0 · Breakout · Security · Python · +0 stars today, ≈ 549 by evening An Agent Skill for Android APK reverse engineering: unpacking, ad removal, dex patching, repacking, and runtime/server analysis. Loaded by an agent (Claude Code, Codex) while it works. Full card: https://gitnova.dev/en/r/newliver666/apk-reverse.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-09-27 01:40 UTC, updated every 30 minutes.