MCP Scan icon

MCP Scan

Scans Model Context Protocol (MCP) servers for common security vulnerabilities like prompt injections and tool poisoning.

About

MCP-Scan is a security scanning tool designed to identify vulnerabilities in your installed MCP servers. It checks for prompt injections, tool poisoning, cross-origin escalations, and MCP rug pull attacks. The tool scans configurations for Claude, Cursor, Windsurf, and other file-based MCP clients, inspecting tool descriptions and utilizing Invariant Guardrails for vulnerability detection. It also offers tool pinning to prevent unauthorized changes and an inspect command to examine tool descriptions.

Key Features

  • Includes an `inspect` command to examine tool descriptions
  • Supports local-only scanning for environments where sharing tool descriptions is not desired.
  • Scans for prompt injection and tool poisoning attacks using Invariant Guardrails
  • 640 GitHub stars
  • Offers tool pinning to detect and prevent MCP rug pull attacks
  • Detects cross-origin escalation attacks (tool shadowing)

Use Cases

  • Securing MCP servers against prompt injection attacks.
  • Preventing tool poisoning and unauthorized modifications to tools.
  • Auditing MCP server configurations for potential vulnerabilities.
Craft Better Prompts with AnyPrompt