Public leaderboard

Public assessment

qianniuspace/mcp-security-audit (mcp-security-audit)

mcp-security-audit · v0.1.0 · scanned

What changed in the harness

Selection accuracy 90→80, token cost up 6%, unconfirmed writes 0%→0%.

Category breakdown

Where the score comes from.

Earned points across the four signals Gradable measures. Safety and Legibility are scored out of 30; Economics and Discoverability are scored out of 20.

01Safety

0.0 / 30

0.0 out of 30
02Legibility

28.0 / 30

28.0 out of 30
03Economics

20.0 / 20

20.0 out of 20
04Discoverability

18.1 / 20

18.1 out of 20

Highest-impact fix

Estimated gain +30 points

Add explicit identity and permission preflight tools

Expose machine-readable principal/tenant confirmation and a non-mutating permission check so agents can verify both before destructive actions.

Description evidence

Defects and rewrites.

1 defect found across the exposed tool descriptions. Suggested rewrites make purpose, inputs, boundaries, and returns easier for an agent to understand.

Tool Defect types Suggested rewrite
audit_nodejs_dependencies
no_return_description
Given a dependencies object from package.json, audit each specified dependency for known vulnerabilities and return a report of the audit findings, indicating which dependencies are vulnerable and the vulnerabilities found.

Selection evidence

Confusable tool pairs.

0 pairs where similar names or overlapping descriptions may send an agent toward the wrong tool.

Tool A Tool B Confidence Why they collide
No confusable tool pairs were flagged in this assessment.

Compare the field

One score is useful.
The evidence makes it actionable.

Back to the leaderboard