Securityscan MCP server
Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout.
0 stars16 downloads/wk
Reviews
Write oneNobody has reviewed Securityscan yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Securityscan tools (8)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
audit_mcp_server_configAudit an MCP client configuration for security risks — works offline, no external service required. Detects: tool poisoning, hidden/coercive instructions in tool descriptions, hardcoded credentials, unpinned packages (rug-pull risk), insecure transport, and toxic capability combinations (shell + network, file-read + network).
check_dependenciesCheck the health of your agent's external dependencies: uptime, SSL validity, blacklist status, and a trust score 0-100 (DepScan).
full_stack_auditComplete security posture in one call: audits the MCP config, checks dependency health, analyzes an untrusted skill, scans the local network gateway, and scans any payload you're about to send out for secrets/PII — then correlates everything into a single prioritized report. Pass only what you have; each section is skipped gracefully if its input or service is missing.
network_scanActive security scan of a device or host with an autonomous AI agent that decides which follow-up probes to run (ActiveScanner). Only scan targets you own or have permission to test.
scan_secretsScan a text payload (a prompt, an outbound API body, a file's contents) for secrets and PII BEFORE it leaves for an LLM or external API, and return a redacted copy. Catches the #1 real-world agent incident: secrets/PII leaking into a model's context.
scan_skillAnalyze an AI agent skill for prompt injection, malware patterns, and OWASP LLM Top 10 issues BEFORE installing it (SecurityScan).
securityscan_checkoutStart a Stripe checkout to buy a SecurityScan tier (agent-native sales). Returns a payment URL to hand to your user AND a PENDING API key that activates automatically once payment clears — no other setup step.
securityscan_pricingSecurityScan catalog: tiers, prices, quotas and the evidence behind the product — the fact sheet an agent needs to evaluate or recommend a purchase to its user. Fully offline, no API key required.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- Code scan5 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 21 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Install directly
claude mcp add securityscan -- uvx securityscan-mcp
Securityscan: common questions
- Is Securityscan MCP server safe?
- Yes, by our scan: it is graded A (89/100). Read the Securityscan safety report
- How do I install Securityscan?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Securityscan need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Securityscan maintained?
- The last commit was 21 days ago (2026-08-30). The latest release is v0.2.0.
- What can I use instead of Securityscan?
- Servers from other publishers that do the same job: SkillTotal MCP server, Skillsmith MCP server and Bomly MCP server. Compare all Securityscan alternatives.
Alternatives to Securityscan
Same job from other publishers: the closest match first, then the best rated.
- SkillTotalDeterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.not reviewedGrowingB
- SkillsmithShare agent skills across your team, scan them for risk, and track what's actually used.not reviewedEstablishedB
- BomlyGive your coding agent the dependency graph it is about to change: scan, diff, explain, auditnot reviewedGrowingB
- mcptoonMCP tools + agent skills in one zero-dependency CLI: 71,929 -> 581 tokens (-99.2%, measured).not reviewedEstablishedA
- Roast My Design SystemAudit your Design System and serve your Agent the rules that keep AI-written UI on-system.not reviewedEstablishedA