AI AGENT ACCESS CONTROL

See what your AI agents can reach.

Map every tool, permission, and data path behind your agents. Find dangerous combinations before one manipulated agent can turn legitimate access into damage.

Know what your agents are using. Before they use it.

Run the same intelligence against your actual MCP configuration—from the CLI, Claude Code, or CI.

$ npx mcp-sec scan

✓ 8 MCP servers discovered

✓ 5 with no tested issue found

! 2 risk conditions need review

✕ 1 confirmed affected version

SCAN RESULT8 / 8 complete
!

filesystem-mcp 1.2.1

Known affected version detected

HIGHPath traversal

Affects versions >=1.0.0 <1.2.4

RECOMMENDED

Upgrade to 1.2.4 or later

Fix independently reproduced · confidence 96%
Evidence-based resultNo tested issue ≠ guaranteed safe
TWO WAYS TO WORK WITH US

Start with an assessment.
Continue with monitoring.

Get a decision-ready picture of today’s exposure, then keep it current as MCP servers, tools, dependencies, and versions change.

ENTERPRISE MONITORING

Know when your MCP risk changes.

Continuous intelligence for every MCP implementation and exact version relevant to your organization.

  • Organization-specific MCP inventory
  • Exact-version risk evidence monitoring
  • Capability and publisher change alerts
  • Historical evidence and decision support
Explore enterprise →
LIVE INTELLIGENCE FEED● LIVE
MCP IMPLEMENTATIONVERSIONVERIFICATIONRISK
Filesystem MCP14 tools · local
2026.8.1VerifiedLow
GitHub MCP Serverwrite access · remote
0.18.0ReviewElevated
Chrome DevTools MCPbrowser control · local
1.7.0VerifiedMedium
New version detectedcontext7@0.5.8Dependency diff queued · 12s ago
WHY MCPSECURITY.CLOUD

Tested.
Version by version.

Most tools match a package name to an advisory. We test the exact MCP version, reproduce the behavior, and show precisely what is affected and how to fix it.

Exact-version testing

We test the release you actually run—not a project name, repository, or generic package family.

Reproducible evidence

Confirmed findings include the input, observed behavior, impact, and independent retest criteria.

Precise affected ranges

Know which versions have confirmed findings, which version contains the fix, and what to upgrade first.

Continuous change detection

New releases, dependency drift, publisher changes, and endpoint behavior stay visible over time.

THE MCP SECURITY RECORD

Trust your agents.
Know their tools.

Explore independently verified intelligence or scan the MCP servers already in your stack.