{"name":"io.github.vpatser1/mcp-server-security-scanner","slug":"vpatser1-mcp-server-security-scanner","title":null,"description":"Scan MCP configs for 30+ CVEs, prompt injection, tool poisoning; validate OAuth configs","url":"https://mcp.market/server/vpatser1-mcp-server-security-scanner","rating":null,"grade":"C","score":55,"certified":false,"status":"active","category":"ai","tags":["ai","security"],"presence":{"score":10,"stars":null,"forks":null,"downloads_week":23,"last_push_at":null,"license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":null,"website":"https://aivp-mcp.vercel.app","version":"1.1.4","remotes":[],"packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"mcp-server-security-scanner","version":"1.1.4","transport":{"type":"stdio"},"environmentVariables":[{"description":"License key (emailed after purchase at https://aivp-mcp.vercel.app). Omit for the free trial (3 calls per tool).","isSecret":true,"name":"LICENSE_KEY"}]}],"tools":[{"name":"check_cves","description":"Checks a list of MCP server names and optional versions against a database of known CVEs in the MCP ecosystem (covering path traversal, SSRF, auth bypass, prompt injection, data exfiltration, command injection, and SQL injection). Returns matching CVEs with severity, CVSS scores, and remediation steps.","write_action":false,"price_micros":0,"input_schema":null},{"name":"generate_report","description":"Generates a comprehensive security report from scan results. Includes an executive summary with overall risk score (0-100), detailed findings with remediation steps, and a SOC 2 compliance checklist. Output is Markdown-formatted.","write_action":false,"price_micros":0,"input_schema":null},{"name":"scan_config","description":"Scans an MCP configuration file (claude_desktop_config.json, .mcp.json, etc.) for security vulnerabilities including hardcoded secrets, excessive permissions, insecure transports, missing authentication, and known vulnerable server versions.","write_action":false,"price_micros":0,"input_schema":null},{"name":"scan_tool_definitions","description":"Analyzes MCP tool definitions for security vulnerabilities including prompt injection vectors, tool poisoning patterns, overly broad filesystem access, command injection risks, and data exfiltration patterns.","write_action":false,"price_micros":0,"input_schema":null},{"name":"validate_auth","description":"Validates OAuth 2.1, API key, or bearer token authentication configuration for an MCP server. Checks for proper PKCE usage, token storage security, redirect URI validation, token expiration settings, and overall auth best practices.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":55,"grade":"C","scanned_at":"2026-09-24T05:07:44.398Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-24T05:07:44.222Z","components":{"code":{"score":25,"max":25,"notes":["21 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":3,"max":15,"notes":["repository not readable: repo not found"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"mcp-server-security-scanner","version":"1.1.4","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":2,"publishedAt":"2026-08-04T07:35:27.124Z","repositoryUrl":"git+https://github.com/vpatser1/mcp-servers.git","weeklyDownloads":23}],"repo":{"found":false,"owner":"vpatser1","repo":"mcp-servers","error":"repo not found"},"icon":{"url":null,"source":"none"},"presence":{"stars":null,"forks":null,"downloadsWeek":23,"license":"MIT","lastPushAt":null,"score":10}}}},"grade_history":[],"reviews":[]}