mcp-scanner — security grade SAFE, quality 78/100

Security audit verdict: SAFE · quality 78/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by cisco-ai-defense · MCP Server · ★ 1.1k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-scanner safe to install? View the security audit →

About mcp-scanner

MCP Scanner A Python tool for scanning MCP (Model Context Protocol) servers and tools for potential security findings. The MCP Scanner combines Cisco AI Defense inspect API, YARA rules and LLM-as-a-judge to detect malicious MCP tools. Overview The MCP Scanner provides a comprehensive solution for scanning MCP servers and tools for security findings. It leverages three powerful scanning engines (Yara, LLM-as-judge, Cisco AI Defense) that can be used together or independently. The SDK is designed to be easy to use while providing powerful scanning capabilities, flexible authentication options, and customization. ![MCP Scanner](https://github.com/cisco-ai-defense/mcp-scanner/r

agentsaimcpsecurity

Quick Facts

Stars1,074
Forks138
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score77.7363015440282/100
Open Issues62
Last Updated2026-09-19
Created2025-09-24
Platformsmcp, python
Est. Tokens~19k

mcp-scanner alternative? Top 6 similar tools

Looking for a mcp-scanner alternative? If you're comparing mcp-scanner with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • solace-agent-mesh by SolaceLabs · ⭐ 4.9k

    An event-driven framework designed to build and orchestrate multi-agent AI systems. It enables seamless integr

  • aci by aipotheosis-labs · ⭐ 4.9k

    ACI.dev is the open source tool-calling platform that hooks up 600+ tools into any agentic IDE or custom AI ag

  • mcp-context-forge by IBM · ⭐ 4.5k

    An AI Gateway, registry, and proxy that sits in front of any MCP, A2A, or REST/gRPC APIs, exposing a unified e

  • dbhub by bytebase · ⭐ 3.5k

    Token conscious database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite.

  • agent-scan by snyk · ⭐ 3.1k

    Security scanner for AI agents, MCP servers and agent skills.

  • toolhive by stacklok · ⭐ 2.2k

    ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is mcp-scanner?

mcp-scanner is Scan MCP servers for potential threats & security findings.. It is categorized as a MCP Server with 1.1k GitHub stars.

What programming language is mcp-scanner written in?

mcp-scanner is primarily written in Python. It covers topics such as agents, ai, mcp.

How do I install or use mcp-scanner?

You can find installation instructions and usage details in the mcp-scanner GitHub repository at github.com/cisco-ai-defense/mcp-scanner. The project has 1.1k stars and 138 forks, indicating an active community.

What license does mcp-scanner use?

mcp-scanner is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to mcp-scanner?

The top alternatives to mcp-scanner on Agent Skills Hub include solace-agent-mesh, aci, mcp-context-forge. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools