mcp-scan audits MCP servers for security flaws
mcp-scan is an open-source CLI that scans MCP configs across major clients before agents trust them. It flags secrets, typosquatting, malicious packages, prompt injection, bad permissions, transport issues, env leaks, and CVEs, with GitHub Actions and SARIF support for CI.
It shifts MCP security left by scanning the configuration before an agent trusts the server. Auto-detecting configurations where developers keep MCP settings makes the scanner practical, and the 10 parallel scanners cover prompt injection, typosquatting, malicious packages, transport security, and dependency CVEs. Integration with CI via SARIF output allows teams to add security gates without changing their existing workflow. The latest v1.0.2 release adds Gemini CLI and project-local config support.
DISCOVERED
18d ago
2026-03-24
PUBLISHED
18d ago
2026-03-24
RELEVANCE
AUTHOR
Github Awesome