Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Make Audit

FreeNot checked

Audits Make.com scenario blueprints before import, checking for hardcoded secrets, dangling references, plain-HTTP URLs, and other issues. Provides tools to ins

GitHubEmbed

About

Audits Make.com scenario blueprints before import, checking for hardcoded secrets, dangling references, plain-HTTP URLs, and other issues. Provides tools to inspect blueprint structure, trace module mappings, and generate a safety findings report.

README

An MCP server that audits Make.com (Integromat) scenario blueprints before you import them. Blueprints are shared everywhere — template galleries, forums, "1000 automation" bundles — and importing one means importing its webhooks, HTTP calls, and whatever credential-shaped strings the author left inside.

  • "What's in this blueprint?" — modules, apps, trigger, routers, error handling, scenario settings
  • "Is it safe to import?" — hardcoded tokens (masked in output), plain-http:// calls, dangling module references, unfiltered router routes, missing error handling, log-retention settings
  • "What feeds module 5?" — mapping-reference tracing in both directions

Make's official MCP runs your scenarios; this one reviews the files before they become scenarios. Local files only.

Quick start

Claude Code

claude mcp add make-audit -- npx -y make-audit-mcp

Claude Desktop — add to claude_desktop_config.json:

{
  "mcpServers": {
    "make-audit": {
      "command": "npx",
      "args": ["-y", "make-audit-mcp"]
    }
  }
}

Then: "Audit C:\Downloads\lead-intake.blueprint.json before I import it."

Tools

Tool What it does
inspect_blueprint Scenario overview: modules, apps, trigger, routers, error handlers, settings
trace_module One module in detail — parameters/mappings (secrets masked), references out and in
audit_blueprint Findings report: errors / warnings / info

What the auditor checks

  • Credential-shaped literals in parameters or mappings (api_key, token, Authorization, Bearer …) — connections are stripped on export, so any literal secret is exactly what shouldn't be in a shared file. Values are masked (supe… (18 chars)) everywhere, including in findings — the auditor never amplifies a leaked token into the model's context.
  • Dangling references — mappings like {{99.output}} pointing at modules that don't exist (common after hand-editing or merging blueprints). The extractor understands Make's expression syntax: {{formatDate(2.date; "X")}} references module 2, while {{parseNumber(3.14)}} references nothing.
  • Plain-http:// URLs, webhook triggers (anyone with the URL can invoke), routers where no route is filtered, disabled-but-present modules, no error handlers with DLQ off, confidential=false log retention.

Known limitation: execution-order validation across router branches is not attempted — reference checks are existence-only.

Development

npm install
npm test                 # offline tests — synthetic blueprints built in-suite
npm run build            # tsc → dist/
node scripts/smoke.mjs   # end-to-end: generates a blueprint, drives the server over stdio

Architecture: src/blueprint.ts (recursive module walk, reference extraction, secret masking) and src/audit.ts (checks) are pure logic; src/index.ts is the MCP wiring. Zero runtime deps beyond the MCP SDK.

Not affiliated with or endorsed by Make / Celonis.

License

MIT

from github.com/arose26/make-audit-mcp

Installing Make Audit

This server has no published package — it is built from source. Open the repository and follow its README.

▸ github.com/arose26/make-audit-mcp

FAQ

Is Make Audit MCP free?

Yes, Make Audit MCP is free — one-click install via Unyly at no cost.

Does Make Audit need an API key?

No, Make Audit runs without API keys or environment variables.

Is Make Audit hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install Make Audit in Claude Desktop, Claude Code or Cursor?

Open Make Audit on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Make Audit with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All development MCPs