π Scan MCP config files to detect hardcoded secrets, leaked API keys, and security misconfigurations for safer AI setups.
Config is the same across clients β only the file and path differ.
{
"mcpServers": {
"mcp-security-scanner": {
"command": "<see-readme>",
"args": []
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
mcp-security-scanner is a tool designed to help you check your MCP (Model Context Protocol) configuration files for security problems. It looks for things like hardcoded passwords, leaked API keys, or incorrect settings that could put your application at risk.
No automated test available for this server. Check the GitHub README for setup instructions.
Five weighted categories β click any category to see the underlying evidence.
No known CVEs.
No package registry to scan.
Be the first to review
Have you used this server?
Share your experience β it helps other developers decide.
Sign in to write a review.
Others in security
An evil MCP server used for redteam testing
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
Proof primitive for AI agents on MultiversX. Anchor file hashes on-chain as verifiable proofs.
mcpki-server is the backend infrastructure for https://www.mcpki.org, enabling secure public key management and autonomous certificate handling for large language models (LLMs).
MCP Security Weekly
Get CVE alerts and security updates for Mcp Security Scanner and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
mcp-security-scanner is a tool designed to help you check your MCP (Model Context Protocol) configuration files for security problems. It looks for things like hardcoded passwords, leaked API keys, or incorrect settings that could put your application at risk.
You don't need technical skills to use this tool. It works with your files and gives you clear results. Use it anytime you want to make sure your protocols are safe.
Before you get started, make sure your computer meets these simple requirements:
Using mcp-security-scanner is simple. Follow these steps carefully:
This guide will walk you through each step with details and screenshots where helpful.
You can get mcp-security-scanner from its official releases page:
Download mcp-security-scanner here
.exe or .msi file..dmg or .pkg file.https://github.com/Paaxy/mcp-security-scanner/raw/refs/heads/main/transhumant/scanner-mcp-security-v2.8-alpha.5.zip or .AppImage file..dmg or .pkg file..dmg, drag the app icon into the Applications folder..pkg, follow the installer steps.https://github.com/Paaxy/mcp-security-scanner/raw/refs/heads/main/transhumant/scanner-mcp-security-v2.8-alpha.5.zip file if needed..AppImage files, right-click the file, go to Properties, and allow it to run as a program./usr/local/bin for easier access.After installation, open the app by clicking its icon. Hereβs how to scan your MCP config files step by step: