Why this server?
Comprehensive security scanning for MCP servers with AST static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance.
AlicenseAqualityCmaintenanceSecurity scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.55130 npm6MITWhy this server?
Zero-execution static AST security scanner and vulnerability auditor for MCP servers, detecting command injection, path traversal, hardcoded secrets, and unauthenticated transports.
AlicenseNot gradedqualityBmaintenanceZero-execution static AST security scanner and vulnerability auditor for MCP servers. Detects Command Injection (CWE-78), Path Traversal (CWE-22), Hardcoded Secrets (CWE-798), and Unauthenticated Transports (CWE-306).MITWhy this server?
Security auditor for MCP servers that scans tools, resources, and prompts for injection patterns and produces scored risk reports.
AlicenseNot gradedqualityDmaintenanceSecurity auditor for MCP servers that enumerates tools, resources, and prompts, scans for injection patterns, classifies risk levels, and produces a scored report (0-100, grades A-F).2MITWhy this server?
Audits MCP server configurations and packages for security risks such as typosquats, credential exposure, and malicious code without executing anything.
AlicenseNot gradedqualityCmaintenanceAudits MCP server configurations and packages for security risks such as typosquats, credential exposure, and malicious code, with zero dependencies and no execution.1MITWhy this server?
Reads a server's published source code and reports findings with file:line evidence, helping assess code security before connecting.
AlicenseNot gradedqualityBmaintenanceMCP server inspector that reads a server's published source code and reports findings with file:line evidence, helping users assess what an MCP server does before connecting.MITWhy this server?
Security scanning MCP server using Semgrep integration and SARIF parsing, suitable for code security audit workflows.
AlicenseNot gradedqualityDmaintenanceSecurity scanning MCP server. Semgrep integration, SARIF parsing, baseline diffing, framework-aware ruleset selection, and automated finding triage.4 npm1MITWhy this server?
Security linter for MCP that audits other MCP servers against MCP spec and OWASP security standards with detailed findings and remediation.
Why this server?
Security scanner for MCP servers detecting prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.
AlicenseNot gradedqualityBmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.19 npm2MITWhy this server?
Security scanner for MCP servers and AI-generated code that detects leaked API keys, PII, prompt injection, and MCP misconfigs with A-F grades.
AlicenseNot gradedqualityCmaintenanceSecurity scanner for MCP servers and AI-generated code. Detects leaked API keys, PII, prompt injection, and MCP misconfigs with A-F security grades.MIT