Hi! Suggesting MCPSafe for the π§βπ Tools and code section.
MCPSafe β Free pre-install security scanner for MCP servers
- Accepts a GitHub URL, npm package, PyPI package, or Docker image
- Runs a 5-LLM consensus panel (Anthropic, Google, Mistral, OpenAI, Meta) to reduce false positives
- Detects: hardcoded secrets/credentials, tool poisoning vectors, SSRF gadgets, transitive CVEs
- Scores findings with AIVSS β an extension of CVSS with agentic-specific threat factors
- Free, no account needed, results in under 60 seconds
We scanned 508 publicly listed MCP servers and found:
- 22% had hardcoded credentials embedded in server code
- 18% had tool poisoning vectors in tool descriptions
- 23% had at least one critical severity issue
Full findings: https://mcpsafe.io/state-of-mcp-security
Suggested entry for the README:
[MCPSafe](https://mcpsafe.io) β Free pre-install scanner for MCP servers. Uses a 5-LLM consensus panel to detect hardcoded secrets, tool poisoning, and SSRF before you connect a server to your agent.
Happy to open a PR if preferred. Thanks for maintaining this list!
Hi! Suggesting MCPSafe for the π§βπ Tools and code section.
MCPSafe β Free pre-install security scanner for MCP servers
We scanned 508 publicly listed MCP servers and found:
Full findings: https://mcpsafe.io/state-of-mcp-security
Suggested entry for the README:
Happy to open a PR if preferred. Thanks for maintaining this list!