mcp-scan
开源 MCP 服务器安全扫描器:审计 Claude Desktop、VS Code、Cursor、Windsurf 等 17 款 AI 客户端的 MCP 配置,检测硬编码密钥、提示注入、工具目录投毒(tool-catalog poisoning)、恶意/仿冒包、CVE 漏洞依赖、网络外联与数据流向分析;结果映射到 SOC 2 / GDPR / HIPAA / PCI-DSS / NIST 合规控制项,支持 SBOM(CycloneDX/SPDX)与 SARIF 输出接入 GitHub Code Scanning。
Install
npx -y Abanoub-Rodolf/mcp-scan
Paste the configuration above into your MCP client config (claude_desktop_config.json for Claude Desktop) and restart the client.
{
"mcpServers": {
"mcp-scan": {
"command": "npx",
"args": [
"-y",
"Abanoub-Rodolf/mcp-scan"
]
}
}
}Paste the configuration above into your MCP client config (claude_desktop_config.json for Claude Desktop) and restart the client.
Sources: public MCP Server directories. This is an independent third-party directory with no affiliation to or endorsement from the maintainers of the listed servers.