MCP-scan – Security scanner for MCP server configs
First security scanner for MCP configs as the protocol gains adoption.
Static source code security analysis for MCP servers
Source-code MCP security auditing. Existing scanners check descriptions; sigil reads actual code.
MCP server developers, AI agent builders, DevOps engineers integrating external tools
Semgrep · Checkmarx
First security scanner for MCP configs as the protocol gains adoption.
MCP-specific guardrails when Claude ecosystem lacks native security scanning.
Five-LLM consensus catches prompt injection patterns static analysis misses.
First static analyzer for MCP servers catching command injection before you plug it in.
Semgrep for AI agents—138 rules, offline, catches obfuscated attacks other scanners miss.
26 MCP-specific checks with GitHub Actions + SARIF, but confined to emerging protocol ecosystem.