robdtaylor/mcpsec - MCP Security Scanner

Scan MCP server configurations for security vulnerabilities: tool poisoning, credential exposure, SSRF, prompt injection, and more.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
config-pathPath to MCP configuration file to scanyes
fail-onMinimum severity to fail the workflow: critical, high, medium, or nonenohigh
namedescription
scoreSecurity score (0-100)
statusScan status: pass, warn, or fail
findingsTotal number of findings
criticalNumber of critical findings
highNumber of high findings