The npm-audit for MCP servers: scan AI agent tools for dangerous permissions, prompt injection, and data exfiltration risks.