XploitScan MCP server
Security scanner for AI-generated code. Scan, explain rules, and grade before you ship.
C65/100grade C
Adoption
New
233 downloads/wk
Reviews
Write oneNobody has reviewed XploitScan yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
XploitScan tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it
no findings
- Code scan1 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Overall 65/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
Runs npx -y xploitscan-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add xploitscan-mcp -- npx -y xploitscan-mcp
XploitScan: common questions
- Is XploitScan MCP server safe?
- With care: it is graded C, so read the findings first (65/100). Read the XploitScan safety report
- How do I install XploitScan?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does XploitScan need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is XploitScan maintained?
- The latest release is v1.5.2.
- What can I use instead of XploitScan?
- Servers from other publishers that do the same job: CodeInspectus MCP server, ScanLabsAI Security Scanner MCP server and MCP server. Compare all XploitScan alternatives.
Alternatives to XploitScan
Same job from other publishers: the closest match first, then the best rated.
- CodeInspectusLocal-first MCP security scanner and CLI for AI-generated applications.not reviewedGrowingC
ScanLabsAI Security ScannerScan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixesnot reviewedNewB- MCPSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.not reviewedGrowingA
- GuardvibeDeterministic security layer your AI can't be. 472 rules, 39 tools, CLI + doctor + host audit.not reviewedGrowingC
- Security Txt Cra Lint13 rules that decide whether a vulnerability report ever reaches younot reviewedGrowingA