rodolfboctor/mcp-scan

Security scanner for MCP server configurations. Detects secrets, CVEs, permission issues, and exfiltration vectors across 10 AI tool clients.

45
/ 100
Emerging

This tool helps security engineers and developers audit the configurations of their AI-powered tools, such as VS Code or GitHub Copilot, to prevent security breaches. It takes your existing AI tool server configurations and provides a detailed report on potential vulnerabilities like leaked secrets, data exfiltration risks, and prompt injection vulnerabilities. Security teams, compliance officers, and developers who use AI tools will find this useful for maintaining a secure environment.

Available on npm.

Use this if you need to identify and mitigate security risks within your AI development ecosystem, including exposed credentials, data flow issues, and supply-chain vulnerabilities.

Not ideal if you are looking for a runtime monitoring solution for live AI server traffic or a tool to enforce real-time alerts.

AI-security application-security software-supply-chain data-privacy compliance-auditing
Maintenance 13 / 25
Adoption 6 / 25
Maturity 18 / 25
Community 8 / 25

How are scores calculated?

Stars

21

Forks

2

Language

TypeScript

License

MIT

Last pushed

Mar 28, 2026

Commits (30d)

0

Dependencies

12

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/rodolfboctor/mcp-scan"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.