MCP-Scan
M
MCP Scan
Overview :
MCP-Scan is a security scanning tool specifically designed for MCP servers. It can detect common security vulnerabilities such as prompt injection and tool poisoning. By checking configuration files and tool descriptions, it helps users ensure system security. Suitable for various developers and system administrators, it is an important tool for maintaining system security.
Target Users :
This product is suitable for developers and system administrators who need to protect their MCP servers from security threats and ensure the security of their tools and systems.
Total Visits: 485.5M
Top Region: US(19.34%)
Website Views : 42.0K
Use Cases
Developers use MCP-Scan to scan their local MCP servers to ensure there are no security vulnerabilities.
System administrators regularly run MCP-Scan to detect and prevent potential tool poisoning attacks.
Enterprises use MCP-Scan to monitor changes in MCP tools to ensure data integrity and security.
Features
Scans MCP client configurations in Claude, Cursor, and Windsurf file formats
Detects prompt injection and tool poisoning attacks in tool descriptions
Identifies cross-site upgrade attacks (tool shadowing attacks)
Detects changes in MCP tools using hashing to prevent MCP rug-pull attacks
Checks the descriptions of installed tools using a command-line tool
How to Use
Install the MCP-Scan tool: Install MCP-Scan via pip.
Run the scan command: Use the command 'uvx mcp-scan@latest' to scan the MCP server.
Specify the configuration file: You can specify the location of the MCP configuration file via parameters.
Set scan options: Set parameters such as the number of checks and timeout as needed.
View scan results: After the scan is complete, check the output results to identify potential security issues.
AIbase
Empowering the Future, Your AI Solution Knowledge Base
© 2025AIbase