{"_id":"@buildwithabid/mcp-shield","_rev":"4-4d30f7d3dbf7db2297a46a6e8d03155a","name":"@buildwithabid/mcp-shield","dist-tags":{"latest":"1.1.2"},"versions":{"1.0.0":{"name":"@buildwithabid/mcp-shield","version":"1.0.0","keywords":["mcp","mcp-security","mcp-scanner","model-context-protocol","security-scanner","vulnerability-scanner","prompt-injection","supply-chain-security","secrets-detection","ai-security","llm-security","claude","mcp-server","audit","static-analysis"],"author":{"name":"BuildWithAbid"},"license":"MIT","_id":"@buildwithabid/mcp-shield@1.0.0","maintainers":[{"name":"buildwithabid","email":"abidtech2017@gmail.com"}],"homepage":"https://github.com/BuildWithAbid/mcp-shield#readme","bugs":{"url":"https://github.com/BuildWithAbid/mcp-shield/issues"},"bin":{"mcp-shield":"dist/index.js"},"dist":{"shasum":"ef41f5a955b4341e176264926e81ae3b4b2911a2","tarball":"https://registry.npmjs.org/@buildwithabid/mcp-shield/-/mcp-shield-1.0.0.tgz","fileCount":75,"integrity":"sha512-TZpJ+caXgizbMdNvvUSWGs31eAL6wiOGCtWUiymBWMBBrUbwaaJOLgJFY6S3EK3LB7eB1TNZqm+LwK4ZPLzRJw==","signatures":[{"sig":"MEUCIQC7WfqLSBD30v8hoWx1yHOWremDViFG6pEjZ8fxmlio1QIgW7UVOQVa7wgk9nhF6MWqLgcxNaVeafxPiN09ck2nUzk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":172967},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":"18 || 20 || >=22"},"gitHead":"1117cf4a90d45a5656be7c8f1a06f34518915f02","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"buildwithabid","email":"abidtech2017@gmail.com"},"repository":{"url":"git+https://github.com/BuildWithAbid/mcp-shield.git","type":"git"},"_npmVersion":"11.9.0","description":"Security scanner for MCP servers. Find vulnerabilities before your AI agent does.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"commander":"^13.1.0","@modelcontextprotocol/sdk":"^1.12.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.1.2","ts-node":"^10.9.2","typescript":"^5.8.3","@types/node":"^22.15.3"},"_npmOperationalInternal":{"tmp":"tmp/mcp-shield_1.0.0_1785668989528_0.3765710366130275","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@buildwithabid/mcp-shield","version":"1.1.0","keywords":["mcp","mcp-security","mcp-scanner","model-context-protocol","security-scanner","vulnerability-scanner","prompt-injection","supply-chain-security","secrets-detection","ai-security","llm-security","claude","mcp-server","audit","static-analysis"],"author":{"name":"BuildWithAbid"},"license":"MIT","_id":"@buildwithabid/mcp-shield@1.1.0","maintainers":[{"name":"buildwithabid","email":"abidtech2017@gmail.com"}],"homepage":"https://github.com/BuildWithAbid/mcp-shield#readme","bugs":{"url":"https://github.com/BuildWithAbid/mcp-shield/issues"},"bin":{"mcp-shield":"dist/index.js"},"dist":{"shasum":"ae5ce2126ea6b300b9aac426db589f23c5ee4cea","tarball":"https://registry.npmjs.org/@buildwithabid/mcp-shield/-/mcp-shield-1.1.0.tgz","fileCount":75,"integrity":"sha512-O0T8An1NCcacta1bYXi72zLywEUNYmD//iR261Sbu1Ac3QmXONawkz45q8/iGYcZPOpLql733Ri+WJklPqBMbA==","signatures":[{"sig":"MEYCIQCnjA9E1k6p42ZR2gviLz/JDaYNnY02zGxgFD2h5OetngIhAJISMTPQfT1qDV9LQ82YbHaVD+MOAKju/iQDnOI7+8Wi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":180245},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":"18 || 20 || >=22"},"gitHead":"dde42766272347774ccddce26defb9ce004c2199","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"buildwithabid","email":"abidtech2017@gmail.com"},"repository":{"url":"git+https://github.com/BuildWithAbid/mcp-shield.git","type":"git"},"_npmVersion":"10.9.8","description":"Security scanner for MCP servers. Find vulnerabilities before your AI agent does.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^13.1.0","@modelcontextprotocol/sdk":"^1.12.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.1.2","ts-node":"^10.9.2","typescript":"^5.8.3","@types/node":"^22.15.3"},"_npmOperationalInternal":{"tmp":"tmp/mcp-shield_1.1.0_1789627205080_0.8890725137312889","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@buildwithabid/mcp-shield","version":"1.1.1","keywords":["mcp","mcp-security","mcp-scanner","model-context-protocol","security-scanner","vulnerability-scanner","prompt-injection","supply-chain-security","secrets-detection","ai-security","llm-security","claude","mcp-server","audit","static-analysis"],"author":{"name":"BuildWithAbid"},"license":"MIT","_id":"@buildwithabid/mcp-shield@1.1.1","maintainers":[{"name":"buildwithabid","email":"abidtech2017@gmail.com"}],"homepage":"https://github.com/BuildWithAbid/mcp-shield#readme","bugs":{"url":"https://github.com/BuildWithAbid/mcp-shield/issues"},"bin":{"mcp-shield":"dist/index.js"},"dist":{"shasum":"f718e41f27e36fa9909051b6f8af5b992b0114cc","tarball":"https://registry.npmjs.org/@buildwithabid/mcp-shield/-/mcp-shield-1.1.1.tgz","fileCount":75,"integrity":"sha512-WPhk/SDuP7wM+bgBk0Etaaqc1q5alnqPGcPC7DPVHkHtayIcck94ipfVr5dRfjSB/GpdzUdNaxH3VenE5ROVXA==","signatures":[{"sig":"MEUCIQCvINDgSgbEKbKgQtBGdBIm22TI/obITxU2GgRnhj8KcwIgdOdmP8emlRwWRJ7Yq6OXm07hysuy1wB8dGvndD0/PiA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIDERpAnMtFZ21MxkdIwttOXo+h6FPS5iPQ4/BuxJP1RWAiEArTUIvbVQXvmPZJPT5v80aGblQ3OBE10C3CRhAvrNinU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":188400},"main":"dist/index.js","types":"./dist/index.d.ts","engines":{"node":"18 || 20 || >=22"},"gitHead":"d3ec06690162b7b560e0becdb29597fa0c880d45","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"buildwithabid","email":"abidtech2017@gmail.com"},"repository":{"url":"git+https://github.com/BuildWithAbid/mcp-shield.git","type":"git"},"_npmVersion":"10.9.8","description":"Security scanner for MCP servers. Find vulnerabilities before your AI agent does.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"commander":"^13.1.0","@modelcontextprotocol/sdk":"^1.12.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.1.2","ts-node":"^10.9.2","typescript":"^5.8.3","@types/node":"^22.15.3"},"_npmOperationalInternal":{"tmp":"tmp/mcp-shield_1.1.1_1790091754303_0.524861153427086","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"_id":"@buildwithabid/mcp-shield@1.1.2","bin":{"mcp-shield":"dist/index.js"},"bugs":{"url":"https://github.com/BuildWithAbid/mcp-shield/issues"},"dist":{"shasum":"81054d993d91f3a0114a91cbf3f05d6d92948254","tarball":"https://registry.npmjs.org/@buildwithabid/mcp-shield/-/mcp-shield-1.1.2.tgz","fileCount":75,"integrity":"sha512-zq4NuVQpHX2/m4c7c0aWr0mhAc8stedvjhlQKR093CwCjFSlPhwkT1g9KuKN70QRUiPwtzRqxklI4f/ZLrNJ0A==","signatures":[{"sig":"MEUCIQCYaqsd2Na7KZWzy/Q7RX4wwlEsy089yKQRHSO333rMZQIgDPp9Dvumc0LTVu0o9+MoWLGWfUxcEbukfkKuwb6XTBM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIA2YHuCyT5Jd7a9lSz0LTvL6zjLNgYPSIZMNrOBnm3xEAiEAi/zuYgwpMHh9i2kiWMoNgWN/I2Ss80SH8AUQ21GvVnw="}],"unpackedSize":189357},"main":"dist/index.js","name":"@buildwithabid/mcp-shield","types":"./dist/index.d.ts","author":{"name":"BuildWithAbid"},"engines":{"node":"18 || 20 || >=22"},"gitHead":"eabdcf0bdf1bd0cb8b2c0080dbee5350ff6e8cc6","license":"MIT","scripts":{"dev":"ts-node src/index.ts","lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest"},"version":"1.1.2","_npmUser":{"name":"buildwithabid","email":"abidtech2017@gmail.com"},"homepage":"https://github.com/BuildWithAbid/mcp-shield#readme","keywords":["mcp","mcp-security","mcp-scanner","model-context-protocol","security-scanner","vulnerability-scanner","prompt-injection","supply-chain-security","secrets-detection","ai-security","llm-security","claude","mcp-server","audit","static-analysis"],"repository":{"url":"git+https://github.com/BuildWithAbid/mcp-shield.git","type":"git"},"_npmVersion":"10.9.8","description":"Security scanner for MCP servers. Find vulnerabilities before your AI agent does.","directories":{},"maintainers":[{"name":"buildwithabid","email":"abidtech2017@gmail.com"}],"_nodeVersion":"22.23.2","dependencies":{"commander":"^13.1.0","@modelcontextprotocol/sdk":"^1.12.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.1.2","ts-node":"^10.9.2","typescript":"^5.8.3","@types/node":"^22.15.3"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-shield_1.1.2_1790225740521_0.6780240755038169"}}},"time":{"created":"2026-08-02T11:09:49.397Z","modified":"2026-09-24T04:55:40.779Z","1.0.0":"2026-08-02T11:09:49.679Z","1.1.0":"2026-09-17T06:40:05.205Z","1.1.1":"2026-09-22T15:42:34.404Z","1.1.2":"2026-09-24T04:55:40.606Z"},"bugs":{"url":"https://github.com/BuildWithAbid/mcp-shield/issues"},"author":{"name":"BuildWithAbid"},"license":"MIT","homepage":"https://github.com/BuildWithAbid/mcp-shield#readme","keywords":["mcp","mcp-security","mcp-scanner","model-context-protocol","security-scanner","vulnerability-scanner","prompt-injection","supply-chain-security","secrets-detection","ai-security","llm-security","claude","mcp-server","audit","static-analysis"],"repository":{"url":"git+https://github.com/BuildWithAbid/mcp-shield.git","type":"git"},"description":"Security scanner for MCP servers. Find vulnerabilities before your AI agent does.","maintainers":[{"name":"buildwithabid","email":"abidtech2017@gmail.com"}],"readme":"<div align=\"center\">\n\n```\n                          _____ __    _      __    __\n   ____ ___  _________   / ___// /_  (_)__  / /___/ /\n  / __ `__ \\/ ___/ __ \\  \\__ \\/ __ \\/ / _ \\/ / __  /\n / / / / / / /__/ /_/ / ___/ / / / / /  __/ / /_/ /\n/_/ /_/ /_/\\___/ .___/ /____/_/ /_/_/\\___/_/\\__,_/\n              /_/\n```\n\n# mcp-shield\n\n**Security scanner for Model Context Protocol (MCP) servers**\n\nFind vulnerabilities, prompt injection, secrets leaks, and supply chain attacks in MCP servers — before your AI agent does.\n\n[![CI](https://github.com/BuildWithAbid/mcp-shield/actions/workflows/ci.yml/badge.svg)](https://github.com/BuildWithAbid/mcp-shield/actions/workflows/ci.yml)\n[![MIT License](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n[![Node.js](https://img.shields.io/badge/node-18%20%7C%2020%20%7C%20≥22-brightgreen.svg)](https://nodejs.org)\n[![TypeScript](https://img.shields.io/badge/TypeScript-5.x-3178c6.svg)](https://www.typescriptlang.org/)\n[![npm](https://img.shields.io/npm/v/@buildwithabid/mcp-shield.svg)](https://www.npmjs.com/package/@buildwithabid/mcp-shield)\n\n[Quick Start](#quick-start) &bull; [Security Checks](#7-security-checks) &bull; [MCP Server Mode](#mcp-server-mode) &bull; [Documentation](#documentation) &bull; [Contributing](#contributing)\n\n</div>\n\n---\n\n## Why mcp-shield?\n\nMCP servers are the new attack surface for AI applications. Recent research has found:\n\n- **66% of MCP servers** have at least one security vulnerability\n- **Tool description injection** is the #1 attack vector — malicious servers embed hidden instructions that manipulate the AI agent\n- **Rug-pull attacks** change tool behavior after a user approves them\n- **Supply chain attacks** through typosquatting and malicious npm packages are increasing\n\n**mcp-shield** is a dedicated security scanner for the MCP ecosystem. It runs 7 security checks against any MCP server package, produces a scored report, and works as both a CLI tool and an MCP server itself.\n\n---\n\n## Quick Start\n\n### Install and Run\n\n```bash\n# Run directly with npx (no install needed)\nnpx @buildwithabid/mcp-shield scan <target>\n\n# Or install globally\nnpm install -g @buildwithabid/mcp-shield\n```\n\n### Scan an MCP Server\n\n```bash\n# Scan an npm package\nnpx @buildwithabid/mcp-shield scan @modelcontextprotocol/server-filesystem\n\n# Scan a local project\nnpx @buildwithabid/mcp-shield scan ./my-mcp-server\n\n# JSON output for CI/CD\nnpx @buildwithabid/mcp-shield scan @some/mcp-server --format json\n\n# Markdown report saved to file\nnpx @buildwithabid/mcp-shield scan @some/mcp-server --format markdown --output report.md\n\n# Quick scan (skip slow checks like rug-pull detection)\nnpx @buildwithabid/mcp-shield scan @some/mcp-server --quick\n```\n\n### Example Output\n\n```\nResolving target: @example/mcp-server-db...\nScanning: @example/mcp-server-db v2.1.0\n\n\n🛡️  mcp-shield v1.1.2 — MCP Security Scanner\n\nScanning: @example/mcp-server-db v2.1.0\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n\n🔴 CRITICAL  Permissions: Unrestricted shell command: \"command\" (dist/tools/execute.js:18)\n🟠 HIGH      Secrets: Generic API Key Assignment detected (dist/config.js:14)\n🟠 HIGH      Transport: Insecure HTTP endpoint (dist/client.js:31)\n🟡 MEDIUM    Transport: Permissive CORS configuration (dist/server.js:9)\n🟢 LOW       Supply Chain: Single maintainer\nℹ️  INFO      Supply Chain: Recently published package\n✅ PASS      Dependencies: No known vulnerabilities\n✅ PASS      Tool Injection: No prompt injection patterns detected\n✅ PASS      Rug-Pull: Tool descriptions are static\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nScore: 47/100 (FAIL)\n1 critical · 2 high · 1 medium · 1 low · 3 pass\n```\n\n---\n\n## 7 Security Checks\n\nmcp-shield runs these scanners against every target:\n\n### 1. Dependency Audit\n\nRuns `npm audit` to find known CVEs in direct and transitive dependencies.\n\n- Severities: Critical, High, Medium, Low\n- Automatically generates a lock file if missing\n\n### 2. Permission & Scope Check\n\nAnalyzes tool input schemas for overly broad permissions:\n\n- **Unrestricted shell commands** — tools that accept arbitrary commands without an enum or allowlist\n- **Unrestricted file paths** — tools without path pattern constraints (path traversal risk)\n- **Raw SQL input** — tools accepting raw SQL strings (SQL injection risk)\n- **Unrestricted URLs** — tools without URL validation (SSRF risk)\n- **eval() / Function()** — dynamic code execution\n- **child_process** — shell access\n\n### 3. Tool Description Injection\n\nScans tool descriptions for prompt injection patterns:\n\n- Hidden instructions (\"ignore previous instructions\", \"do not tell the user\")\n- Role/persona override (\"you are now\", \"act as\")\n- Unicode tricks (zero-width characters, homoglyphs, RTL overrides)\n- Base64-encoded payloads\n- Markdown/HTML injection\n- Data exfiltration patterns\n\n### 4. Rug-Pull Detection\n\nDetects mutable tool descriptions that can change after approval:\n\n- Descriptions loaded from environment variables or config\n- Descriptions generated by function calls or network requests\n- Timer-based tool modification (`setTimeout`/`setInterval`)\n- Post-registration tool changes (`setTools`, `updateTool`)\n\n### 5. Secrets Detection\n\nFinds hardcoded secrets in source code and `.env` files:\n\n- AWS keys, OpenAI/Anthropic API keys, GitHub tokens\n- Stripe, Slack, Google, Twilio, SendGrid keys\n- Database connection strings, JWTs, private keys\n- Generic password/token/secret assignments\n- Smart placeholder detection (skips `\"your-key-here\"` etc.)\n\n### 6. Transport Security\n\nChecks transport-layer configuration:\n\n- HTTP instead of HTTPS for remote endpoints (loopback `localhost`, `127.0.0.1`, `0.0.0.0` and `[::1]` is exempt)\n- Permissive CORS (`Access-Control-Allow-Origin: *`)\n- Credentials with wildcard CORS origin\n- Auth tokens in URL query strings\n- Disabled TLS verification (`rejectUnauthorized: false`)\n- Unprotected sensitive routes\n\n### 7. Supply Chain Analysis\n\nChecks npm metadata and package integrity.\n\nPackage scans query the npm registry:\n\n- **Typosquatting detection** via Levenshtein distance against known MCP packages\n- Recently published packages (< 30 days), reported as info with no score penalty\n- Single-maintainer risk\n- Packages mimicking official naming\n- Missing or minimal package description\n\nPackage and local scans both read the target's `package.json`:\n\n- Suspicious lifecycle scripts (`preinstall`, `postinstall`, `preuninstall`, `postuninstall`). npm runs these on install, so a package scan reports them before you install.\n- Scripts downloading remote code\n- Missing repository declaration\n\n---\n\n## MCP Server Mode\n\nmcp-shield also runs as an MCP server, so AI assistants can scan other MCP servers directly:\n\n```bash\n# Start the MCP server\nnpx @buildwithabid/mcp-shield serve\n\n# Add to Claude Code\nclaude mcp add mcp-shield -- npx @buildwithabid/mcp-shield serve\n```\n\n### Available MCP Tools\n\n| Tool | Description |\n|------|-------------|\n| `scan_package` | Scan an npm MCP server package by name (package scan) |\n| `scan_local` | Scan a local directory for security issues (local scan) |\n| `get_report` | Get the last scan report (JSON, Markdown, or terminal format) |\n\n---\n\n## Documentation\n\n### CLI Reference\n\n```\nUsage: mcp-shield scan [options] <target>\n\nScan an MCP server package or local directory for security vulnerabilities\n\nArguments:\n  target                 npm package name or local path to scan\n\nOptions:\n  -f, --format <format>  Output format: terminal, json, markdown (default: \"terminal\")\n  -o, --output <file>    Write report to file\n  -q, --quick            Skip slow checks (rug-pull detection) (default: false)\n  -h, --help             display help for command\n```\n\n```\nUsage: mcp-shield serve [options]\n\nRun mcp-shield as an MCP server\n\nOptions:\n  -h, --help  display help for command\n```\n\n`mcp-shield --version` prints the installed version. With `--output`, the report is written to the file and also printed. The MCP server uses the stdio transport.\n\nA target that starts with `.`, `/` or `~`, or is any absolute path, is a local path; anything else is looked up on npm. Relative paths resolve against the current directory, absolute paths are used as given, and a leading `~` expands to your home directory.\n\n### What Gets Scanned\n\nmcp-shield reads source and config files under the target: JavaScript and TypeScript, Python, JSON, YAML, TOML, INI and XML config, `.env` files, shell scripts, and Ruby, Go, Rust, Java, Kotlin, C#, PHP and Terraform files. Which directories it skips depends on the kind of scan:\n\n| Directories | Local scan (a path on disk) | Package scan (downloaded from npm) |\n|-------------|-----------------------------|------------------------------------|\n| `node_modules/`, `.git/`, `coverage/`, `__pycache__/`, `.venv/`, `venv/`, `.tox/`, `.mypy_cache/`, `.pytest_cache/` | Skipped | Skipped |\n| `dist/`, `build/`, `out/`, `.next/` | Skipped: this is your own build output, and bundled chunks produce false findings for code you never wrote | Scanned: it is often the only code a published package ships |\n\nIn both kinds of scan mcp-shield also skips:\n\n- Build tooling that never reaches a client: `build.js`/`.mjs`/`.ts`, `gulpfile.js`, `Gruntfile.js`, `esbuild.config.js`/`.mjs`, and `rollup`, `webpack`, `vite`, `jest`, `vitest`, `babel`, `eslint`, `prettier`, `tsup`, `tailwind`, `postcss` and `commitlint` config files\n- Compiled `.js` when the `.ts` it came from sits beside it, and a `.d.ts` when its `.js` sits beside it, so each finding is reported once\n- Files larger than 1 MB\n\n### Output Formats\n\n| Format | Flag | Best For |\n|--------|------|----------|\n| Terminal | `--format terminal` (default) | Human-readable with colors and severity icons |\n| JSON | `--format json` | CI/CD pipelines, programmatic access |\n| Markdown | `--format markdown` | GitHub issues, pull requests, wikis |\n\n### Scoring System\n\nEvery scan starts at 100. Findings are counted per severity, and each severity deducts `unit × √count`, up to a cap:\n\n| Severity | Unit | Cap | 1 finding | 4 findings | Cap reached at | Examples |\n|----------|------|-----|-----------|------------|----------------|----------|\n| Critical | 25 | 60 | -25 | -50 | 6 findings | eval(), unrestricted shell command, TLS verification disabled, AWS key, typosquatting |\n| High | 15 | 40 | -15 | -30 | 8 findings | child_process call, insecure HTTP endpoint, generic API key, unrestricted file path |\n| Medium | 5 | 20 | -5 | -10 | 16 findings | Filesystem write, permissive CORS, no repository declared |\n| Low | 2 | 8 | -2 | -4 | 16 findings | Filesystem read, environment variable access, single maintainer |\n| Info | 0 | 0 | 0 | 0 | never | Recently published package, audit could not run |\n| Pass | 0 | 0 | 0 | 0 | never | Check passed cleanly |\n\nThe result is rounded and never goes below 0. The square root means the tenth instance of a pattern costs less than the first. The cap means no single severity can sink a package on its own: a long tail of low findings costs at most 8 points. The example above scores 100 − 25 − 15×√2 − 5 − 2 = 46.8, shown as 47.\n\n**Score ≥ 70** = PASS. **Score < 70** = FAIL. The CLI exits with code 0 on PASS and 1 on FAIL (also 1 if the target cannot be resolved), and 2 if the scan itself errors, so CI can gate on it.\n\n### Architecture\n\n```\n                  ┌─────────────┐\n                  │   CLI / MCP  │  (index.ts / mcp-server.ts)\n                  │   Server     │\n                  └──────┬───────┘\n                         │\n                  ┌──────▼───────┐\n                  │ Orchestrator │  (scanner/index.ts)\n                  │  File Cache  │  Collects files once, shares across scanners\n                  └──────┬───────┘\n                         │\n        ┌────────┬───────┼───────┬────────┬────────┬────────┐\n        ▼        ▼       ▼       ▼        ▼        ▼        ▼\n   ┌────────┐┌───────┐┌──────┐┌───────┐┌───────┐┌───────┐┌───────┐\n   │Secrets ││ Deps  ││ Tool ││ Perms ││Rug-Pull││ Trans ││Supply │\n   │  Leak  ││ Audit ││ Desc ││ Check ││Detect  ││  Sec  ││ Chain │\n   └────────┘└───────┘└──────┘└───────┘└───────┘└───────┘└───────┘\n        │        │       │       │        │        │        │\n        └────────┴───────┴───────┴────────┴────────┴────────┘\n                         │\n                  ┌──────▼───────┐\n                  │   Reporter   │  Terminal / JSON / Markdown\n                  └──────────────┘\n```\n\nAll 7 scanners run concurrently using `Promise.allSettled`, sharing a single file cache for maximum performance.\n\n---\n\n## Use Cases\n\n### CI/CD Pipeline\n\n```bash\n# Fail the build if the MCP server has security issues\nnpx @buildwithabid/mcp-shield scan ./my-mcp-server --format json\n# Exit code 1 if score < 70\n```\n\n### Pre-Install Check\n\n```bash\n# Check an MCP server package before installing it\nnpx @buildwithabid/mcp-shield scan @unknown/mcp-server-database\n```\n\n### Security Audit\n\n```bash\n# Generate a markdown report for a security review\nnpx @buildwithabid/mcp-shield scan @company/internal-mcp-server --format markdown --output audit-report.md\n```\n\n### AI-Assisted Scanning\n\n```bash\n# Let Claude scan MCP servers from within a conversation\nclaude mcp add mcp-shield -- npx @buildwithabid/mcp-shield serve\n# Then ask: \"Scan @modelcontextprotocol/server-filesystem for security issues\"\n```\n\n---\n\n## Contributing\n\nContributions are welcome! See [CONTRIBUTING.md](CONTRIBUTING.md) for setup instructions and guidelines.\n\n### Areas Where Help Is Needed\n\n- **New detection patterns** — prompt injection techniques, secret formats, dangerous APIs\n- **Live server scanning** — connecting to running MCP servers to test tool responses\n- **PyPI / pip support** — extending to Python MCP servers\n- **CI/CD integrations** — GitHub Actions workflow, pre-commit hooks\n- **Documentation** — guides, tutorials, real-world examples\n\n---\n\n## Related Projects\n\n- [Model Context Protocol](https://modelcontextprotocol.io) — the protocol specification\n- [MCP TypeScript SDK](https://github.com/modelcontextprotocol/typescript-sdk) — official TypeScript SDK\n- [Claude Code](https://docs.anthropic.com/en/docs/claude-code) — AI coding assistant with MCP support\n\n---\n\n## License\n\n[MIT](LICENSE) — free for personal and commercial use.\n\n\n---\n\n**Available for MCP work** — tool surface reviews, production builds, and keeping them running afterwards. Scope and fixed prices: **[The Write Path](https://claude.ai/artifact/F1w4szMDEa6e4NonRyFqp6)**\n\nBuilt by [Abid Ali](https://github.com/buildwithabid), who runs a guarded MCP server over live invoices and statutory filing deadlines every working day. 📬 support@bizfilo.com\n","readmeFilename":"README.md"}