MCP Watch 🔍

Created By
kapilduraphea year ago
A comprehensive security scanner for Model Context Protocol (MCP) servers that detects vulnerabilities and security issues in your MCP implementations.
Overview

What is MCP Watch?

MCP Watch is a comprehensive security scanner designed to detect vulnerabilities and security issues in Model Context Protocol (MCP) servers, ensuring the integrity and safety of MCP implementations.

How to use MCP Watch?

To use MCP Watch, install it via npm and run it from the command line to scan your MCP server repositories for vulnerabilities.

Key features of MCP Watch?

  • Credential Detection: Identifies hardcoded API keys and insecure credential storage.
  • Tool Poisoning Detection: Scans for hidden malicious instructions in tool descriptions.
  • Parameter Injection Detection: Finds magic parameters that may extract sensitive AI context.
  • Prompt Injection Scanning: Detects prompt manipulation and injection attacks.
  • Input Validation Checks: Identifies command injection and path traversal issues.

Use cases of MCP Watch?

  1. Scanning GitHub repositories for security vulnerabilities in MCP servers.
  2. Ensuring compliance with security best practices in AI tool implementations.
  3. Identifying and mitigating risks associated with credential leaks and server spoofing.

FAQ from MCP Watch?

  • Can MCP Watch scan any repository?

Yes, it can scan any GitHub repository that implements MCP.

  • Is MCP Watch free to use?

Yes, MCP Watch is open-source and free to use.

  • How accurate is the vulnerability detection?

MCP Watch is designed to be highly accurate, but results may vary based on the complexity of the implementation.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
kapilduraphe
Star
0
Language
TypeScript
License
MIT license
Category
security

Recommend Servers

View All
Bring your real authenticated browser session to AI coding agents. Local-first MCP server + Chrome MV3 extension. No cloud. No telemetry.
@Cubenest

peek records the user's actual logged-in browser (DOM via rrweb, console events, network metadata, optional response bodies via opt-in Deep capture) through a Chrome MV3 extension. The extension ships events through a native-messaging stdio bridge to a local MCP server (peek-mcp), which persists them to a SQLite database at ~/.peek/sessions.db. AI coding agents (Claude Code, Cursor, Cline, Windsurf) read sessions from the database via 10 MCP tools: Tool What it does list_recent_sessions List recently recorded sessions (id, origin, ts, event count). get_session_summary LLM-readable narrative summary of a session. get_session_console_errors Console errors recorded in a session. get_session_network_errors Failed/notable network requests in a session. get_user_action_before_error Last N user actions before a console error. generate_playwright_repro Generate a runnable Playwright test from a session. get_dom_snapshot Reconstruct the DOM at a given timestamp. query_dom_history Timeline of attribute/text changes for a selector. request_authorization Side-panel consent for write actions (Level 3). execute_action Dispatch a UI action (gated by permission level + destructive blocklist). Why local-first matters Every other "browser session for AI" tool ships to a vendor cloud. peek's SQLite + extension live on the user's machine — no remote endpoints, no telemetry. The privacy policy (docs/peek/PRIVACY_POLICY.md) is the source of truth. Install # 1. Add the MCP server to Claude Code claude mcp add peek -- npx -y @peekdev/mcp # 2. Install the Chrome extension from the Chrome Web Store # (link added once the CWS listing is approved)

a day ago
Crevio

2 days ago