nhomyk/MCP Security Scan

Scan MCP servers & AI agents for tool poisoning, SSRF, prompt injection & DataFlow taint. SARIF output. No API key.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
repo-pathPath to the repository to scan (default: current directory)no.
fail-on-criticalExit with code 1 if any critical findings are discoverednofalse
sarif-outputFilename for the SARIF output filenomcp-scan-results.sarif
upload-sarifUpload SARIF to GitHub Code Scanning (requires security-events: write permission in the calling workflow) notrue
categoryGitHub Code Scanning SARIF category (useful when running multiple scans)nomcp-security
namedescription
findings-countTotal number of findings across all scan types
risk-levelOverall risk level: low | medium | high | critical
critical-countNumber of critical findings
sarif-filePath to the generated SARIF output file