MCP-Scan: An MCP Security Scanner

Created By
invariantlabs-ai7 months ago
A security scanning tool for MCP servers
Overview

what is MCP-Scan?

MCP-Scan is a security scanning tool designed to check installed MCP servers for common security vulnerabilities such as prompt injections, tool poisoning, and cross-origin escalations.

how to use MCP-Scan?

To use MCP-Scan, run the command uvx mcp-scan@latest in your terminal to initiate the scanning process on your MCP server configurations.

key features of MCP-Scan?

  • Scans for prompt injection attacks in tool descriptions.
  • Detects cross-origin escalation attacks.
  • Tool pinning to prevent MCP rug pull attacks.
  • Inspecting tool descriptions of installed tools.

use cases of MCP-Scan?

  1. Identifying security vulnerabilities in MCP server configurations.
  2. Ensuring the integrity of tools used in MCP environments.
  3. Preventing potential security breaches through proactive scanning.

FAQ from MCP-Scan?

  • What types of vulnerabilities does MCP-Scan check for?

MCP-Scan checks for prompt injections, tool poisoning, and cross-origin escalations.

  • Is my data safe when using MCP-Scan?

Yes, MCP-Scan does not store or log any usage data, ensuring your configurations remain private.

  • How can I contribute to MCP-Scan?

Contributions are welcome! You can open an issue on the GitHub repository for suggestions or bug reports.

Project Info
Created At
7 months ago
Updated At
7 months ago
Author Name
invariantlabs-ai
Star
610
Language
Python
License
Apache-2.0 license
Category
security
Tags

Recommend Servers

View All
Saifsai

an hour ago
Remote

a day ago
Ahammedshaik
@f

2 days ago