Mcp Scan
@Chris79OG
About Mcp Scan
MCP server security scanner that detects vulnerability patterns in MCP server configurations and outputs SARIF reports. Scans for prompt injection risks, tool poisoning, excessive permissions, and other security issues in Model Context Protocol servers.
Config
Add this server to your MCP-compatible client using the configuration below.
{
"mcpServers": {
"mcp-scan": {
"command": "npx",
"args": [
"@syntrophy/mcp-scan"
]
}
}
}Tools
No tools detected
Fetch the live tool list by running this server in a temporary sandbox using the button above.
Overview
What is Mcp Scan?
Mcp Scan is a security scanner for MCP servers. It detects common vulnerability patterns such as prompt injection and tool poisoning, flags excessive permissions, and outputs its findings as SARIF 2.1.0 reports.
How to use Mcp Scan?
Run it directly via npx without installation: npx @syntrophy/mcp-scan. No other configuration or invocation details are provided in the README.
Key features of Mcp Scan
- Detects prompt injection risks
- Identifies tool poisoning patterns
- Flags excessive permissions
- Outputs standard SARIF 2.1.0 reports
- Runs without persistent installation via npx
Use cases of Mcp Scan
- Auditing an MCP server for prompt injection vulnerabilities
- Scanning for tool poisoning before deploying an MCP server
- Checking an MCP server’s permission model for over‑broad access
- Generating SARIF reports for integration with CI/CD pipelines
FAQ from Mcp Scan
What vulnerability types does Mcp Scan detect?
It detects prompt injection risks, tool poisoning patterns, and excessive permissions.
How do I install Mcp Scan?
Installation is not required; run it directly with npx @syntrophy/mcp-scan.
What output format does the scanner produce?
It outputs standard SARIF 2.1.0 reports.
Is Mcp Scan a standalone CLI tool?
Yes, it is executed as a one‑off command via npx; no explicit runtime dependencies are mentioned in the README.
Frequently asked questions
What vulnerability types does Mcp Scan detect?
It detects prompt injection risks, tool poisoning patterns, and excessive permissions.
How do I install Mcp Scan?
Installation is not required; run it directly with `npx @syntrophy/mcp-scan`.
What output format does the scanner produce?
It outputs standard SARIF 2.1.0 reports.
Is Mcp Scan a standalone CLI tool?
Yes, it is executed as a one‑off command via npx; no explicit runtime dependencies are mentioned in the README.
Basic information
More Developer Tools MCP servers

discoverGPT
Joe MonastierodiscoverGPT is visualAI's unified MCP gateway for AI commerce, exposing 29 tools across four capabilities on one canonical product catalog: trimodal search (natural-language, precise-color, and image-similarity), AI cata
Vibgrate MCP
VibgrateQuery your team's drift, vulnerability, and migration data from any AI assistant. Vibgrate MCP connects Cursor, Claude, ChatGPT, Windsurf, or VS Code to Vibgrate Cloud: 51 tools for DriftScores, CVEs and EOL runtimes, up

Meticulous
MeticulousMCP server and skills to connect to the Meticulous UI testing platform.

BetterBugs
BetterBugsThe BetterBugs MCP (Model Context Protocol) enables you to load BetterBugs bug reports (via report links) directly to your preferred AI Agents and developer environments with MCP Client capabilities (such as Cursor, VS C

PuzzleTide Puzzle Generator
Caravaca-LabsWord search generator, crossword generator, and sudoku generator + solver as a local-first MCP server. 15 deterministic tools: printable PDF puzzle worksheets, themed word banks, and verifiable LLM evals. From the makers
Comments