Mcpaudit – static security scanner for MCP servers
First static analyzer for MCP servers catching command injection before you plug it in.
MCP security scanner by Helixar
26 MCP-specific checks with GitHub Actions + SARIF, but confined to emerging protocol ecosystem.
DevOps engineers, security teams, and developers deploying MCP servers
Trivy (container scanning) · TruffleHog (secret detection) · CloudMapper (cloud misconfig)
First static analyzer for MCP servers catching command injection before you plug it in.
First security scanner for MCP configs as the protocol gains adoption.
MCP-specific guardrails when Claude ecosystem lacks native security scanning.
Catches typosquatting and leaked secrets in MCP configs before deployment.
Seven-dimension security scoring catches fail-open errors before your MCP gateway hits production.
Semgrep for AI agents—138 rules, offline, catches obfuscated attacks other scanners miss.