MCP-scan – Security scanner for MCP server configs
First security scanner for MCP configs as the protocol gains adoption.

MCP-native security scanning inside Cursor beats switching to Snyk dashboards.
Developers using AI coding assistants
Snyk · Semgrep · GitHub Advanced Security
First security scanner for MCP configs as the protocol gains adoption.
Wraps Bandit and Semgrep into one Django-specific security CLI.
First static analyzer for MCP servers catching command injection before you plug it in.
MCP-specific guardrails when Claude ecosystem lacks native security scanning.
26 MCP-specific checks with GitHub Actions + SARIF, but confined to emerging protocol ecosystem.
Bundles CI-friendly scanners that target agent-specific risks: 17 patterned secret detectors, prompt-injection and instruction‑malware heuristics, tool/SSRF and MCP auth checks, plus SARIF/JSON outputs for integration. Findings map to the OWASP Top 10 for Agentic Applications (2026) and it adds 'harden' profiles to apply safer defaults to OpenClaw/MCP installs — practical, focused ops tooling rather than a generic secret-finder.