scan_target
Audit an MCP server target by analyzing source, package manifests, and optional Docker-sandboxed runtime behavior; returns security findings.
Instructions
Scan an MCP server target with the full detection core: source analysis, package manifests, and (optionally, dynamic=True) live execution inside the Docker sandbox. Returns the findings.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes | Server directory, mcp.json path, or raw stdio launch command. | |
| dynamic | No | Also run the dynamic layer (Docker sandbox required; the target always runs sandboxed). Default: false. | |
| timeout | No | Per-call timeout seconds (default 30). |