We built mcp-customs, a free, offline CLI that checks an MCP server for

common security risks before you install it — think npm audit, but

for the servers your AI agent connects to. Before asking anyone to use

it, we pointed it at 12 real, popular MCP servers and read every single

finding by hand. Here's what actually held up.