Skip to content

Security MCP Server

Agent Security Scanner MCP

Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

Scan flagged something by sinewaveai85MITJavaScriptIntermediatestdio
View on GitHub Install Guide

Install

Claude Code

claude mcp add agent-security-scanner-mcp -- npx -y agent-security-scanner-mcp

Safety Report

43% Scan flagged something
Scanned 5 months ago
3 passed 3 warnings 1 failed
Security
Authentication
details

Authentication detected: env_api_key, env_api_key_py, bearer_check, jwt_verify, connection_string, oauth

Pass
CORS Policy
details

stdio transport — CORS not applicable

N/A
Rate Limiting
details

Rate limiting detected: rate_limit_middleware, express_rate_limit

Pass
Known CVEs
details

1 deps with known issues (medium)

Warning
Code Quality
Dependency Audit
details

1 deps with known issues (medium)

Warning
Dangerous Patterns
details

Critical dangerous patterns: sql_concat

Fail
License
details

License: MIT

Pass
Community
Maintenance Status
details

Last commit 5 months ago

Warning

Learn about our security methodology →

Compatibility

Claude CodeFull support
Tested
CursorFull support
Tested
VS CodeFull support via Copilot
Tested
WindsurfFull support
Tested
Claude DesktopFull support
Tested

Frequently Asked Questions

What is Agent Security Scanner MCP?

Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

Is Agent Security Scanner MCP safe to use?

We cannot tell you that, and nobody scanning at this scale can. What we did in March 2026 was shallow-clone Agent Security Scanner MCP and run five keyword searches over its source: auth identifiers, CORS configuration, rate-limit identifiers, the dependency manifest against a hardcoded list of 18 known-vulnerable packages, and unguarded eval/exec calls. At least one matched — the specific finding is in the scan report on this page. A text search cannot follow a variable, judge intent, or tell you what a server does once it is running, so "nothing matched" is not "safe". What the scan does and does not cover is written out at /mcp/security.

What are alternatives to Agent Security Scanner MCP?

Similar MCP servers include GhidraMCP, Ida Pro MCP, Beelzebub. Each serves a similar purpose but may differ in features, language, and compatibility.

Similar MCP Servers

GhidraMCP

Not scanned
by LaurieWired

A Model Context Protocol server for Ghidra that enables LLMs to autonomously reverse engineer applications. Provides tools for decompiling binaries, renaming methods and data, and listing methods, classes, imports, and exports.

security Java stdio
7.9k 27 tools
View

Ida Pro MCP

Scan flagged something
by mrexodia

MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

security Python stdio
6.4k 25 tools
View

Beelzebub

Scan found nothing
by mariocandela

Beelzebub is a honeypot framework that lets you build honeypot tools using MCP. Its purpose is to detect prompt injection or malicious agent behavior. The underlying idea is to provide the agent with tools it would never use in its normal work.

security Go stdio
1.9k
View
Was this helpful?

Free AI writing tools

Check a draft for AI tells, then fix what the check finds.

Stay Updated on MCP Servers

New servers, safety alerts, and install guides — weekly.