MCP-scan – security scanner for MCP server configs
Catches typosquatting and leaked secrets in MCP configs before deployment.
The most comprehensive MCP security scanner — attack paths, tool poisoning, typosquats, CVEs, trust scores, rug-pull detection
Attack graph across MCP servers catches chains no single-server scanner finds; solves actual new problem.
AI assistant power users, Claude/Cursor configuration managers, security teams vetting AI tool plugins
MCPShield · Snyk · Enkrypt
Catches typosquatting and leaked secrets in MCP configs before deployment.
Semgrep for AI agents—138 rules, offline, catches obfuscated attacks other scanners miss.
Correlates AWS findings into attack chains with Terraform fix scripts.
First security scanner for MCP configs as the protocol gains adoption.
First static analyzer for MCP servers catching command injection before you plug it in.
MCP-specific guardrails when Claude ecosystem lacks native security scanning.