meok-mcp-injection-scan-mcp
Related Servers
Alternatives to meok-mcp-injection-scan-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceScans MCP servers for security vulnerabilities, prompt injection, and tool poisoning, providing risk scores and protection.4MIT
- AlicenseNot gradedqualityCmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.8 npm2MIT
- AlicenseCqualityBmaintenanceSecurity scanner and MCP server that catches dangerous patterns in MCP servers and AI agent projects, such as leaked secrets, shell execution, and prompt-injection text. Runs as both a CLI and MCP server with CI-friendly severity gates.21MIT
- AlicenseNot gradedqualityAmaintenanceScans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.19MIT
- AlicenseNot gradedqualityBmaintenanceScans MCP servers, AI agent skills, and plugins for 68+ malicious patterns including credential exfiltration, prompt injection, and code execution.49 npm6MIT
- AlicenseBqualityDmaintenanceAutomated security red-team for any MCP server that scans manifests against OWASP LLM Top 10 and MCP-specific risks, returning a 0-100 hardening score and HMAC-signed report.7MIT
TDQS
Scored across 5 tools
Each tool targets a distinct aspect of the security scanning workflow: 'audit_tool_descriptions' handles local JSON analysis, 'scan_mcp_url' handles remote scanning, 'list_rules' lists detection rules, 'pricing' provides subscription details, and 'signed_safety_report' generates a signed certificate. No two tools have overlapping purposes.
The naming convention is mostly snake_case but inconsistent in structure: three tools follow a verb_noun pattern ('audit_tool_descriptions', 'list_rules', 'scan_mcp_url'), while 'pricing' is a bare noun and 'signed_safety_report' uses a past participle adjective-noun form. This mix reduces predictability.
With 5 tools, the server is well-scoped for its purpose of scanning MCP servers for injection vulnerabilities. Each tool serves a clear function without overlap, and the count is appropriate for a focused security assessment tool.
The tool surface covers the core workflow: local audit, remote scan, rule listing, pricing, and signed reporting. Minor gaps exist (e.g., no tool for configuration or result history), but these are not essential for the primary use case. Overall, the surface is sufficiently complete for its domain.