Scans Model Context Protocol (MCP) servers for common security vulnerabilities like prompt injections and tool poisoning.
MCP-Scan is a security scanning tool designed to identify vulnerabilities in your installed MCP servers. It checks for prompt injections, tool poisoning, cross-origin escalations, and MCP rug pull attacks. The tool scans configurations for Claude, Cursor, Windsurf, and other file-based MCP clients, inspecting tool descriptions and utilizing Invariant Guardrails for vulnerability detection. It also offers tool pinning to prevent unauthorized changes and an inspect command to examine tool descriptions.