MCP SECURITY SCANNER

Understand the risk in every MCP your agents use.

Discover every configured MCP. Identify exact versions. Separate confirmed findings from capability, package-integrity, and configuration risk conditions.

A clean scan means no tested or known issue was found under this scan profile. It is not a guarantee of absolute safety.
mcp-sec — scan
$ npx mcp-sec scan

 Discovering MCP configurations...
 Claude Code        5 servers
 Cursor             3 servers

Checking 8 implementations against intelligence... 

NO TESTED ISSUE  5
RISK CONDITION   2
CONFIRMED        1

filesystem-mcp@1.2.1
Path traversal · fixed in 1.2.4

→ Upgrade: npm i filesystem-mcp@^1.2.4
ONE COMMAND · FOUR ANSWERS
01

What am I using?

Discover MCPs across Claude Code, Cursor, configuration files, packages, and remote endpoints.

02

Which exact version?

Resolve immutable versions, integrity hashes, repository commits, and endpoint fingerprints.

03

What can it do?

Map filesystem, shell, database, browser, cloud, credentials, and destructive capabilities.

04

What should I change?

Get evidence, affected ranges, fixed versions, safer configuration, and clear next actions.

INSTALL

Start with your stack.

No account required for the local scan. Intelligence lookups use version-specific public records.

npx mcp-sec scan
COMMON QUESTIONS

MCP security scanner FAQ

What does the MCP security scanner check?

It discovers configured MCP servers, resolves exact versions, checks known vulnerability evidence and package integrity, and flags risk conditions involving commands, capabilities, transports, and permissions.

Which MCP clients can it scan?

The scanner checks MCP configurations used by Claude Code, Cursor, VS Code, Codex, and compatible configuration files.

Does a clean scan guarantee an MCP server is safe?

No. A clean result means no tested or known issue was found under the scan profile. It is evidence for a decision, not a guarantee of absolute safety.