Security Scanner MCP server
Scan MCP configs for 30+ CVEs, prompt injection, tool poisoning; validate OAuth configs
23 downloads/wk
Reviews
Write oneNobody has reviewed Security Scanner yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Security Scanner tools (5)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
check_cvesChecks a list of MCP server names and optional versions against a database of known CVEs in the MCP ecosystem (covering path traversal, SSRF, auth bypass, prompt injection, data exfiltration, command injection, and SQL injection). Returns matching CVEs with severity, CVSS scores, and remediation steps.
generate_reportGenerates a comprehensive security report from scan results. Includes an executive summary with overall risk score (0-100), detailed findings with remediation steps, and a SOC 2 compliance checklist. Output is Markdown-formatted.
scan_configScans an MCP configuration file (claude_desktop_config.json, .mcp.json, etc.) for security vulnerabilities including hardcoded secrets, excessive permissions, insecure transports, missing authentication, and known vulnerable server versions.
scan_tool_definitionsAnalyzes MCP tool definitions for security vulnerabilities including prompt injection vectors, tool poisoning patterns, overly broad filesystem access, command injection risks, and data exfiltration patterns.
validate_authValidates OAuth 2.1, API key, or bearer token authentication configuration for an MCP server. Checks for proper PKCE usage, token storage security, redirect URI validation, token expiration settings, and overall auth best practices.
Public scan report
scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it
- Code scan21 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Install directly
Runs npx -y mcp-server-security-scanner on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add mcp-server-security-scanner -- npx -y mcp-server-security-scanner
Security Scanner: common questions
- Is Security Scanner MCP server safe?
- With care: it is graded C, so read the findings first (55/100). Read the Security Scanner safety report
- How do I install Security Scanner?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Security Scanner need an API key?
- Yes. The registry entry asks for
LICENSE_KEY. - Is Security Scanner maintained?
- The latest release is v1.1.4.
- What can I use instead of Security Scanner?
- Servers from other publishers that do the same job: Agent-Native Analytics MCP server, Godot MCP server and Image MCP server. Compare all Security Scanner alternatives.
Alternatives to Security Scanner
Same job from other publishers: the closest match first, then the best rated.
- Agent-Native AnalyticsAgent-Native Amplitude/Mixpanel - connect data sources, prompt for chartsnot reviewedEstablishedA
- Godot MCPAgent-driven Godot playtesting: editor control, input injection, game-time stepping, live state.not reviewedEstablishedA
- ImageAI image generation and editing with prompt optimization and quality presetsnot reviewedEstablishedB
- llmtrimMCP server and proxy that compresses LLM prompts, tool output, and replies to cut token cost.not reviewedEstablishedA
- SkillsmithShare agent skills across your team, scan them for risk, and track what's actually used.not reviewedEstablishedB