Skip to main content
Glama
CSOAI-ORG

meok-mcp-injection-scan-mcp

Related Servers

Alternatives to meok-mcp-injection-scan-mcp

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      D
      maintenance
      Scans MCP servers for security vulnerabilities, prompt injection, and tool poisoning, providing risk scores and protection.
      4
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Security scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.
      8 npm
      2
      MIT
    • A
      license
      C
      quality
      B
      maintenance
      Security scanner and MCP server that catches dangerous patterns in MCP servers and AI agent projects, such as leaked secrets, shell execution, and prompt-injection text. Runs as both a CLI and MCP server with CI-friendly severity gates.
      2
      1
      MIT
    • A
      license
      Not graded
      quality
      A
      maintenance
      Scans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.
      19
      MIT
    • A
      license
      B
      quality
      D
      maintenance
      Automated security red-team for any MCP server that scans manifests against OWASP LLM Top 10 and MCP-specific risks, returning a 0-100 hardening score and HMAC-signed report.
      7
      MIT

    TDQS

    A3.9/5.0

    Scored across 5 tools

    Disambiguation5/5

    Each tool targets a distinct aspect of the security scanning workflow: 'audit_tool_descriptions' handles local JSON analysis, 'scan_mcp_url' handles remote scanning, 'list_rules' lists detection rules, 'pricing' provides subscription details, and 'signed_safety_report' generates a signed certificate. No two tools have overlapping purposes.

    Naming Consistency3/5

    The naming convention is mostly snake_case but inconsistent in structure: three tools follow a verb_noun pattern ('audit_tool_descriptions', 'list_rules', 'scan_mcp_url'), while 'pricing' is a bare noun and 'signed_safety_report' uses a past participle adjective-noun form. This mix reduces predictability.

    Tool Count5/5

    With 5 tools, the server is well-scoped for its purpose of scanning MCP servers for injection vulnerabilities. Each tool serves a clear function without overlap, and the count is appropriate for a focused security assessment tool.

    Completeness4/5

    The tool surface covers the core workflow: local audit, remote scan, rule listing, pricing, and signed reporting. Minor gaps exist (e.g., no tool for configuration or result history), but these are not essential for the primary use case. Overall, the surface is sufficiently complete for its domain.

    Maintenance

    ActivityInactive
    ResponsivenessUnresponsive