MCP Security scanner
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_detectorsA | List every detector in the deepsleuth registry: id, category, evidence location, phase, and required capability layers. |
| check_listingA | Analyze a supplied MCP tool listing with the listing-phase detectors (description/schema poisoning, shadowing, obfuscation, ...) WITHOUT launching the server. Pass another server's tools/list output. |
| scan_targetB | Scan an MCP server target with the full detection core: source analysis, package manifests, and (optionally, dynamic=True) live execution inside the Docker sandbox. Returns the findings. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
check_listing and scan_target both perform scanning, but descriptions clearly scope check_listing to listing-phase detectors without launching the server, while scan_target runs the full core with source/manifest analysis and optional Docker dynamic execution. list_detectors is clearly a registry enumeration. Boundaries are mostly distinct with only mild conceptual overlap.
All three tools follow a consistent verb_noun snake_case pattern (check_listing, list_detectors, scan_target). No mixing of conventions, styles, or casing.
Three tools is on the lean side but well-scoped for a focused MCP security scanner: a listing-only check, a full scan, and detector enumeration. Each earns its place, though a slightly richer surface could be expected for a detection framework.
Core workflows (static listing analysis, full source/manifest/dynamic scan, detector discovery) are covered, and check_listing vs scan_target provide both lightweight and deep paths. Minor gaps exist: no per-finding detail/retrieval, no report export, and no detector configuration management, but agents can work around these.