The first dedicated offensive security auditor for MCP servers Threat Landscape · Checks · Install · Usage · CVEs · Output 🔥 Threat Landscape MCP has become the standard for connecting AI agents to the real world — and attackers got there first. Researchers have already documented: Compromised npm packages spawning malic
| Stars | 8 |
| Forks | 2 |
| Language | TypeScript |
| Category | MCP 服务器 |
| License | MIT |
| Quality Score | 34.85/100 |
| Last Updated | 2026-03-12 |
| Created | 2026-03-10 |
| Platforms | mcp, node |
| Est. Tokens | ~200k |
These tools work well together with MCPScan for enhanced workflows:
Explore other popular mcp 服务器 tools:
MCPScan is Offensive MCP server auditor — detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.. It is categorized as a MCP 服务器 with 8 GitHub stars.
MCPScan is primarily written in TypeScript. It covers topics such as ai-security, llm-security, mcp.
You can find installation instructions and usage details in the MCPScan GitHub repository at github.com/sahiloj/MCPScan. The project has 8 stars and 2 forks, indicating an active community.
MCPScan is released under the MIT license, making it free to use and modify according to the license terms.