MCPVet
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCPVetscan GitHub repo https://github.com/owner/repo for malicious code"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCPVet MCP server
Vet an MCP server, Claude Code skill, or plugin for unsafe behavior — shell execution, secret access, data exfiltration, prompt injection, remote code — before you install it, right inside your agent.
It's a thin, auditable client: all analysis runs server-side at mcpvet.com. This process holds no credentials, touches no local files, and makes exactly one outbound HTTPS call per scan.
Install (Claude Code)
claude mcp add mcpvet -- npx -y github:LorenzoLombardi111/factory-mcpvetOr add it to your MCP config manually:
{
"mcpServers": {
"mcpvet": {
"command": "npx",
"args": ["-y", "github:LorenzoLombardi111/factory-mcpvet"]
}
}
}Related MCP server: mcp-security-audit
Use
Ask your agent:
Before I install it, scan
@some/mcp-serverwith MCPVet.
The scan_extension tool accepts:
a GitHub repo URL —
https://github.com/owner/repoan npm package name —
@scope/pkgpasted skill / manifest text
It returns a graded verdict (clean → critical), the flagged findings with file and line, and a shareable report link.
Config
Env | Default | Purpose |
|
| API origin (override for self-host/testing) |
MIT licensed.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityAmaintenanceScans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.Last updated5MIT
- Alicense-qualityBmaintenanceScans MCP servers, AI agent skills, and plugins for 68+ malicious patterns including credential exfiltration, prompt injection, and code execution.Last updated1085MIT
- AlicenseAqualityBmaintenanceVet ClawHub skills before installing them; detects prompt-injection, exfiltration, and other security issues, outputting a risk score with per-finding evidence.Last updated7MIT
- AlicenseAqualityAmaintenanceEnables scanning of Claude Code skills, plugins, or MCP servers for malware before installation via static analysis.Last updated114MIT
Related MCP Connectors
Verify a skill, tool, or package for malicious behavior before your agent installs it. Hosted.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/LorenzoLombardi111/factory-mcpvet'
If you have feedback or need assistance with the MCP directory API, please join our Discord server