MCP-scan – Security scanner for MCP server configs
First security scanner for MCP configs as the protocol gains adoption.

Verifying ownership with a DNS TXT record and spinning up ephemeral Cloud Run jobs to produce a PDF report in under an hour is a pragmatic approach — cheap to operate and low-friction for SMBs. It's explicitly automated (no manual pentest), which keeps expectations honest, but the market already has mature scanners and few standout differentiators here beyond pricing and convenience; continuous monitoring, remediation guidance or integrations would make it much more compelling.
Small business owners, MSPs, IT admins, and non‑technical operators who need affordable, no‑friction vulnerability scans
What it does: Enter a domain you own, verify ownership via DNS TXT record, and Radar runs a full scan — subdomain enumeration, DNS recon, port and service scanning, and vulnerability assessment (OWASP Top 10, infrastructure flaws, exposed assets). You get a PDF report in under 60 minutes.
What it is not: This isn't a penetration test. There's no manual exploitation or business logic testing. It's automated vulnerability scanning — the security baseline that most small businesses skip because pentests are $10k+ and confusing to buy.
Tech: Serverless on Google Cloud Run. Each scan spins up, runs, and tears down. Pay-as-you-go at $99/scan — no subscriptions.
Free during beta: Radar is in beta right now and Stripe is in test mode, so scans are free. Use test card 4111 1111 1111 1111 (exp: 11/11, cvc: 111) at checkout.
Try it: https://www.oscarsixsecurityllc.com/#solutions
Happy to answer questions about the scanning methodology, architecture, or anything else.
First security scanner for MCP configs as the protocol gains adoption.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Security scanner for Q-Day migration when Snyk doesn't track this yet.
AI pentesting framework when Burp Suite and OWASP ZAP already dominate.
AI security scanner with auto-fix PRs, competing directly with Snyk and CodeQL.
OWASP MCP Top 10 scanner and proxy firewall for AI agent tool calls.