Offensive MCP server auditor — detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.
MCPScan is an open-source security auditing tool designed to identify vulnerabilities and misconfigurations in MCP servers used by AI agents.
How It Works
You hear about a helpful security checker for AI tool connections that spots hidden dangers.
You grab the tool and get it ready on your computer in just a few moments.
You tell it to check your AI setups or look around for any open connections on your machine.
Safely reviews files where your AI tools are listed.
Looks for any exposed connections right on your computer.
You receive a clear, color-coded list of any risks with easy fixes.
Your AI tool connections are now checked and protected from common threats.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.