Golf Scanner – OSS tool to find and audit every MCP server
Closes the MCP server discovery gap that shadow-IT has made critical.
Open Source Agentic Security Scanner
Actually spins up Docker to exploit findings instead of just flagging them.
Security teams, open-source maintainers, developers concerned about codebase vulnerabilities
Snyk · Semgrep · CodeQL
Closes the MCP server discovery gap that shadow-IT has made critical.
First security scanner for MCP configs as the protocol gains adoption.
Cross-scanner CVE deduplication keyed on advisory ID saves real triage time.
First static analyzer for MCP servers catching command injection before you plug it in.
40 scanners in one command when GitHub Advanced Security already exists.
Single-file, zero-dep scanner for a niche product, but OpenClaw audience is tiny.