Factual package intelligence from PyPI
Static analyzer for MCP server repos: 6 checks (BadHost / Starlette CVE-2026-48710, FastMCP wrapper-layer asyncio.run bug, loose @mcp.tool() schemas, subprocess command-injection w/ cross-function taint propagation, destructive-filesystem sinks from tool params, keyword-guarded S
pip install mcpdone-audit
PyPI declares 2 unique dependency rules for this release. Environment markers are shown when supplied by the project.
>=23.0mcpdone-audit publishes 1 wheel and 1 source archive for version 0.8.0. Wheel platform tags: any.
Declared Python classifiers: 3.11, 3.12.
An OSV query completed on and found 0 known vulnerabilities affecting this version. 0 advisories are classified as critical. 0 advisories appear in the CISA Known Exploited Vulnerabilities catalog.
PyPI lists 4 releases with files. The first dated release is ; 4 releases fall within the 365 days preceding the latest dated release. The current release files were uploaded on . The preceding dated release was .