CLI tool for MCP server security scanning
Top 39.9% on sourcepulse
MCP-Scan is a security auditing tool for Model Context Protocol (MCP) servers, designed to identify vulnerabilities like prompt injection, tool poisoning, and cross-origin escalations in AI agent configurations. It targets developers and users of MCP-based systems, offering automated checks and insights into tool security.
How It Works
MCP-Scan analyzes MCP server configuration files, retrieves tool descriptions, and scans them for vulnerabilities. It employs local checks and leverages Invariant Guardrails via an API for enhanced security analysis. Tool names and descriptions are shared with invariantlabs.ai for security research, with users agreeing to terms of use and privacy policies.
Quick Start & Requirements
uvx mcp-scan@latest
or npx mcp-scan@latest
npx
), UV (for uvx
). No specific hardware or OS dependencies mentioned.Highlighted Details
inspect
command for viewing tool descriptions without verification.Maintenance & Community
mcpscan@invariantlabs.ai
.Licensing & Compatibility
Limitations & Caveats
The tool shares tool descriptions and names with invariantlabs.ai for security research, which may be a concern for users with strict data privacy requirements. The specific license and its implications for commercial use are not clearly defined.
3 days ago
1 day