Skip to main content
Glama
DeepSleuth

MCP Security scanner

Official

Related Servers

Alternatives to MCP Security scanner

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      Enforces deterministic security policies as an inline firewall for MCP server tool calls, with AST-based validation, cryptographic audit logging, and CLI-based evaluation and verification.
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Proxies MCP traffic between a client and a downstream server to enforce runtime policies on tool declarations, call arguments, and results, including allowlisting, sandboxing, secret and egress controls, and injection detection. It also includes a deterministic benchmark for measuring which security controls stop which attacks.
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Self-hosted MCP gateway that applies deterministic, compiled policy to tool discovery, invocation, and outbound data flow, with no model in the enforcement path. Every decision emits a hash-chained receipt sealed with Ed25519 and verifiable using public keys only.
      Apache 2.0
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables enterprise MCP security auditing through 12 deterministic no-LLM tools for evidence-gated claims, skill/prompt supply-chain audits, token profiling, and server auth-mode checks.
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Enables security auditing of MCP servers by running them in a sandbox with fake secrets, capturing outbound traffic, and detecting tool poisoning or secret exfiltration before approval.
      8 npm
      MIT

    TDQS

    A3.7/5.0

    Scored across 3 tools

    Disambiguation4/5

    check_listing and scan_target both perform scanning, but descriptions clearly scope check_listing to listing-phase detectors without launching the server, while scan_target runs the full core with source/manifest analysis and optional Docker dynamic execution. list_detectors is clearly a registry enumeration. Boundaries are mostly distinct with only mild conceptual overlap.

    Naming Consistency5/5

    All three tools follow a consistent verb_noun snake_case pattern (check_listing, list_detectors, scan_target). No mixing of conventions, styles, or casing.

    Tool Count4/5

    Three tools is on the lean side but well-scoped for a focused MCP security scanner: a listing-only check, a full scan, and detector enumeration. Each earns its place, though a slightly richer surface could be expected for a detection framework.

    Completeness4/5

    Core workflows (static listing analysis, full source/manifest/dynamic scan, detector discovery) are covered, and check_listing vs scan_target provide both lightweight and deep paths. Minor gaps exist: no per-finding detail/retrieval, no report export, and no detector configuration management, but agents can work around these.

    Maintenance

    ActivityActive
    ResponsivenessNo issues