No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by cisco-ai-defense · MCP Server · ★ 1.1k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp-scanner safe to install? View the security audit →
MCP Scanner A Python tool for scanning MCP (Model Context Protocol) servers and tools for potential security findings. The MCP Scanner combines Cisco AI Defense inspect API, YARA rules and LLM-as-a-judge to detect malicious MCP tools. Overview The MCP Scanner provides a comprehensive solution for scanning MCP servers and tools for security findings. It leverages three powerful scanning engines (Yara, LLM-as-judge, Cisco AI Defense) that can be used together or independently. The SDK is designed to be easy to use while providing powerful scanning capabilities, flexible authentication options, and customization.  servers.
Explore other popular mcp server tools:
mcp-scanner is Scan MCP servers for potential threats & security findings.. It is categorized as a MCP Server with 1.1k GitHub stars.
mcp-scanner is primarily written in Python. It covers topics such as agents, ai, mcp.
You can find installation instructions and usage details in the mcp-scanner GitHub repository at github.com/cisco-ai-defense/mcp-scanner. The project has 1.1k stars and 138 forks, indicating an active community.
mcp-scanner is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to mcp-scanner on Agent Skills Hub include solace-agent-mesh, aci, mcp-context-forge. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: