knostic/MCP-Scanner

Advanced Shodan-based scanner for discovering, verifying, and enumerating Model Context Protocol (MCP) servers and AI infrastructure tools over HTTP & SSE.

47
/ 100
Emerging

This tool helps security professionals identify and analyze publicly accessible Model Context Protocol (MCP) servers and associated AI infrastructure. It takes a Shodan API key as input to search for MCP servers, then verifies their protocol compliance and enumerates their capabilities. The output includes detailed JSON and CSV reports, along with a human-readable summary, enabling cybersecurity teams to assess the security posture of AI deployments.

Use this if you are a security researcher, penetration tester, or part of a cybersecurity team needing to discover, verify, and assess the security of Model Context Protocol (MCP) servers and AI infrastructure for data governance, attack surface management, or compliance.

Not ideal if you are looking for a general-purpose network scanner or if your goal is to test systems without explicit authorization.

AI Security Cybersecurity Research Attack Surface Management Data Governance Compliance Auditing
No Package No Dependents
Maintenance 10 / 25
Adoption 7 / 25
Maturity 15 / 25
Community 15 / 25

How are scores calculated?

Stars

37

Forks

7

Language

Python

License

MIT

Last pushed

Mar 11, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/knostic/MCP-Scanner"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.