{"_id":"mcp-server-security-scanner","_rev":"11-5ca0e9a48ea11c9ad12f335347eb4ce9","name":"mcp-server-security-scanner","dist-tags":{"latest":"1.1.4"},"versions":{"1.1.1":{"name":"mcp-server-security-scanner","version":"1.1.1","keywords":["mcp","security","scanner","vulnerability","model-context-protocol"],"author":"","license":"MIT","_id":"mcp-server-security-scanner@1.1.1","maintainers":[{"name":"aivp","email":"wasuppeople3@gmail.com"}],"bin":{"mcp-server-security-scanner":"dist/index.js"},"dist":{"shasum":"50fe6fe5ab9bdd2d279f395b893c4f9f0a37219c","tarball":"https://registry.npmjs.org/mcp-server-security-scanner/-/mcp-server-security-scanner-1.1.1.tgz","fileCount":32,"integrity":"sha512-S0c8EDD02PQJQqrUW/NN6q14Rzlr9tyonjQzS07PvjcTV03g6d/5bBPbQQvIMgCCe93qx6wp/zgoqhUcyA+ztA==","signatures":[{"sig":"MEUCIQCiPmVzfHnuqVURT9wX9C5DlHTFvJrVw1QiH1X461TgjAIgPwXmx1oLIOjd39Gl8hPpSW0hattW6fNn3k6nbE1NjdA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":125757},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"4c2db3d7214a1ecbb45e5c3d246105a0288cd2ea","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","start:http":"node dist/index.js --http","start:stdio":"node dist/index.js --stdio","prepublishOnly":"npm run build"},"_npmUser":{"name":"aivp","email":"wasuppeople3@gmail.com"},"_npmVersion":"11.11.0","description":"MCP server that scans MCP configurations, tool definitions, and code for security vulnerabilities","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^3.25.0","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^22.0.0","@types/express":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-security-scanner_1.1.1_1774963702780_0.45732892611480125","host":"s3://npm-registry-packages-npm-production"}},"1.1.3":{"name":"mcp-server-security-scanner","version":"1.1.3","keywords":["mcp","security","scanner","vulnerability","model-context-protocol"],"author":"","license":"MIT","_id":"mcp-server-security-scanner@1.1.3","maintainers":[{"name":"aivp","email":"wasuppeople3@gmail.com"}],"bin":{"mcp-server-security-scanner":"dist/index.js"},"dist":{"shasum":"98556ca56660aada0fb0391981fee278fdc5a731","tarball":"https://registry.npmjs.org/mcp-server-security-scanner/-/mcp-server-security-scanner-1.1.3.tgz","fileCount":22,"integrity":"sha512-yY7Jse8gaAMwhsccvbAYnmF3Gnsq0xmPEW4/+WKlMS0v3uGon7k7tPNkUyyCeJdcZEDMXA0RSx/xuopFZVsh5A==","signatures":[{"sig":"MEUCIQDiKWmihBxn0l+IlWW6hBGPG/im/kfkZAWq7BC2TL7cGAIgTE9h274whHzrdF6+uOBv4Gl4qX8krs4COwwSDR8fQyE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":118510},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"90f4c3072f2309527d7163ea89461f69604894e2","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js","start:http":"node dist/index.js --http","start:stdio":"node dist/index.js --stdio","prepublishOnly":"npm run build"},"_npmUser":{"name":"aivp","email":"wasuppeople3@gmail.com"},"_npmVersion":"11.11.0","description":"MCP server that scans MCP configurations, tool definitions, and code for security vulnerabilities","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^3.25.0","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^22.0.0","@types/express":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-security-scanner_1.1.3_1775025171428_0.9984558623961901","host":"s3://npm-registry-packages-npm-production"}},"1.1.4":{"name":"mcp-server-security-scanner","version":"1.1.4","description":"MCP server that scans MCP configurations, tool definitions, and code for security vulnerabilities","mcpName":"io.github.vpatser1/mcp-server-security-scanner","repository":{"type":"git","url":"git+https://github.com/vpatser1/mcp-servers.git","directory":"security-scanner"},"homepage":"https://aivp-mcp.vercel.app","type":"module","main":"dist/index.js","bin":{"mcp-server-security-scanner":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js","start:stdio":"node dist/index.js --stdio","start:http":"node dist/index.js --http","dev":"tsc --watch","prepublishOnly":"npm run build"},"keywords":["mcp","security","scanner","vulnerability","model-context-protocol"],"author":"","license":"MIT","dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","zod":"^3.25.0"},"devDependencies":{"@types/express":"^5.0.0","@types/node":"^22.0.0","typescript":"^5.8.0"},"engines":{"node":">=18.0.0"},"gitHead":"31655a90ad0cac3d56211a1e7a88dccaaef73640","types":"./dist/index.d.ts","_id":"mcp-server-security-scanner@1.1.4","bugs":{"url":"https://github.com/vpatser1/mcp-servers/issues"},"_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-0/B36/Hg5hEK/bDCnooNAhcFKvi2trATynveg5FOduVQd5y3UQGOF9QhWcpJ9CYgZ1WtBrmifNtxwv7DUTwn0Q==","shasum":"e1772f21c49aa969f661e804f3ff93f761e848a5","tarball":"https://registry.npmjs.org/mcp-server-security-scanner/-/mcp-server-security-scanner-1.1.4.tgz","fileCount":22,"unpackedSize":126010,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDXi9pNPlHkvFEAgYVJ6kAMzNzaNSC26XWLB6JAielfZAIhAP+QkZeq8rxUmfg2YqyKn+PTH4bvbUmPMglAFMYpkWny"}]},"_npmUser":{"name":"aivp","email":"wasuppeople3@gmail.com"},"directories":{},"maintainers":[{"name":"aivp","email":"wasuppeople3@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server-security-scanner_1.1.4_1785828926980_0.6888565441443104"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-31T11:25:06.841Z","modified":"2026-08-04T07:35:27.308Z","1.0.1":"2026-03-31T11:25:07.114Z","1.0.2":"2026-03-31T12:41:29.780Z","1.1.0":"2026-03-31T12:58:54.427Z","1.1.1":"2026-03-31T13:28:22.948Z","1.1.2":"2026-04-01T06:26:30.815Z","1.1.3":"2026-04-01T06:32:51.607Z","1.1.4":"2026-08-04T07:35:27.124Z"},"license":"MIT","keywords":["mcp","security","scanner","vulnerability","model-context-protocol"],"description":"MCP server that scans MCP configurations, tool definitions, and code for security vulnerabilities","maintainers":[{"name":"aivp","email":"wasuppeople3@gmail.com"}],"readme":"# MCP Security Scanner\n\nA production-grade MCP (Model Context Protocol) server that scans MCP configurations, tool definitions, and server deployments for security vulnerabilities.\n\n## Why This Matters\n\nThe MCP ecosystem experienced a surge of security disclosures in late 2025 and early 2026:\n\n- **30+ CVEs** were published affecting MCP servers between January and February 2026 alone.\n- **82% of MCP implementations** tested by security researchers were vulnerable to path traversal attacks.\n- Tool poisoning and prompt injection via malicious tool descriptions emerged as a novel attack vector unique to AI tool ecosystems.\n- Several incidents involved data exfiltration through MCP servers that accepted arbitrary URLs while also accessing sensitive local data.\n\nMCP Security Scanner helps you find these issues before attackers do.\n\n## Features\n\n| Tool | What It Does |\n|------|-------------|\n| `scan_config` | Scans MCP config files for hardcoded secrets, excessive permissions, insecure transports, missing auth, and known vulnerable servers |\n| `scan_tool_definitions` | Detects prompt injection, tool poisoning, overly broad filesystem access, command injection risks, and data exfiltration patterns in tool definitions |\n| `check_cves` | Checks server names/versions against a curated database of 20 known MCP CVEs covering path traversal, SSRF, auth bypass, prompt injection, and more |\n| `validate_auth` | Validates OAuth 2.1, API key, and bearer token configurations for PKCE, token storage, redirect URIs, expiration, and best practices |\n| `generate_report` | Produces a Markdown report with risk score (0-100), detailed findings, remediation steps, and SOC 2 compliance checklist |\n\n## Pricing\n\n| Plan | Price | |\n|------|-------|---|\n| **Free trial** | $0 | 3 calls total (shared across all tools), no credit card — just run it |\n| **Personal** | $19/mo | [Buy →](https://buy.stripe.com/5kQ3cn0HU8UkevpfbVgIo03) |\n| **Team** | $79/mo | [Buy →](https://buy.stripe.com/28EdR162e6Mc4UP5BlgIo04) |\n| **Enterprise** | $499/mo | [Buy →](https://buy.stripe.com/dRm00b76i6Mcbjd5BlgIo05) |\n\nLicense keys are emailed instantly after checkout. Activate via the `LICENSE_KEY` environment variable. More info: [aivp-mcp.vercel.app](https://aivp-mcp.vercel.app)\n\n## Installation\n\n> **Note:** the npm package is **`mcp-server-security-scanner`** (not the bare name `security-scanner`).\n\nNo install step needed — run straight from npm:\n\n```bash\nnpx -y mcp-server-security-scanner\n```\n\nOr install globally:\n\n```bash\nnpm install -g mcp-server-security-scanner\n```\n\n## Usage\n\n### As a stdio MCP server (recommended for local use)\n\nAdd to your Claude Desktop configuration (`claude_desktop_config.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"security-scanner\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"mcp-server-security-scanner\"],\n      \"env\": { \"LICENSE_KEY\": \"<your license key — omit for free trial>\" }\n    }\n  }\n}\n```\n\nOr add the same block to your project's `.mcp.json`.\n\n### As an HTTP server (for remote/shared deployments)\n\n```bash\n# Start on default port 3000\nnpx -y mcp-server-security-scanner --http\n\n# Or specify a port\nPORT=8080 npx -y mcp-server-security-scanner --http\n```\n\nConnect clients to `http://localhost:3000/mcp` using Streamable HTTP transport.\n\n## Tool Reference\n\n### scan_config\n\nScans an MCP configuration file for security issues.\n\n**Input:**\n```json\n{\n  \"configPath\": \"~/.claude/claude_desktop_config.json\"\n}\n```\n\n**Checks performed:**\n- Hardcoded API keys, tokens, passwords, and private keys (11 secret patterns)\n- Servers running with root/elevated privileges\n- Docker containers without security restrictions\n- Deno/Node processes with unrestricted permissions\n- stdio servers without container/sandbox isolation\n- HTTP servers missing authorization headers\n- Plain HTTP (non-TLS) connections to remote servers\n- Servers matching known vulnerable package names\n\n### scan_tool_definitions\n\nAnalyzes tool definitions for prompt injection and other attack vectors.\n\n**Input:**\n```json\n{\n  \"tools\": [\n    {\n      \"name\": \"read_file\",\n      \"description\": \"Reads a file from the filesystem\",\n      \"inputSchema\": {\n        \"type\": \"object\",\n        \"properties\": {\n          \"path\": { \"type\": \"string\", \"description\": \"File path to read\" }\n        }\n      }\n    }\n  ]\n}\n```\n\n**Checks performed:**\n- Hidden system instructions in tool descriptions\n- Role override / instruction boundary escape attempts\n- Invisible Unicode characters hiding payloads\n- Cross-tool manipulation directives\n- Data collection and exfiltration instructions\n- Approval/confirmation bypass patterns\n- Unrestricted path/command/URL parameters\n- Overly broad filesystem access patterns\n- Unusually long descriptions (>2000 chars)\n\n### check_cves\n\nChecks servers against the built-in CVE database.\n\n**Input:**\n```json\n{\n  \"servers\": [\n    { \"name\": \"@modelcontextprotocol/server-filesystem\", \"version\": \"0.5.0\" },\n    { \"name\": \"mcp-server-git\" }\n  ]\n}\n```\n\nTo list all CVEs in the database:\n```json\n{\n  \"servers\": [],\n  \"listAll\": true\n}\n```\n\n**CVE database covers:**\n- Path traversal (5 CVEs) -- including symlink and Unicode normalization variants\n- SSRF (2 CVEs) -- direct and redirect-based\n- Authentication bypass (3 CVEs) -- OAuth state forgery, missing SSE auth, API key leaks\n- Prompt injection (3 CVEs) -- tool description injection, registry poisoning, stored injection\n- Data exfiltration (2 CVEs) -- DNS rebinding, URL-based data encoding\n- Command injection (2 CVEs) -- shell metacharacters, unsanitized git refs\n- SQL injection (1 CVE) -- string concatenation queries\n\n### validate_auth\n\nValidates authentication configuration against best practices.\n\n**Input:**\n```json\n{\n  \"authConfig\": {\n    \"type\": \"oauth\",\n    \"oauth\": {\n      \"clientId\": \"my-app\",\n      \"authorizationUrl\": \"https://auth.example.com/authorize\",\n      \"tokenUrl\": \"https://auth.example.com/token\",\n      \"redirectUri\": \"https://myapp.com/callback\",\n      \"scopes\": [\"read\", \"write\"],\n      \"pkce\": true,\n      \"tokenExpiration\": 3600,\n      \"refreshTokenRotation\": true\n    }\n  }\n}\n```\n\n**Checks performed:**\n- OAuth 2.1 compliance (PKCE requirement, required fields)\n- Client secret storage (should not be in config files)\n- Redirect URI security (HTTPS, no wildcards, valid scheme)\n- Token expiration settings (flags >1 hour or non-expiring)\n- Token storage method (flags localStorage, plaintext)\n- Refresh token rotation\n- Scope configuration (least privilege)\n- API key and bearer token storage\n\n### generate_report\n\nGenerates a comprehensive Markdown security report.\n\n**Input:** Pass the results from any combination of the other four tools:\n```json\n{\n  \"configScan\": { \"...\" : \"result from scan_config\" },\n  \"toolScan\": { \"...\" : \"result from scan_tool_definitions\" },\n  \"cveCheck\": { \"...\" : \"result from check_cves\" },\n  \"authValidation\": { \"...\" : \"result from validate_auth\" }\n}\n```\n\n**Report includes:**\n- Executive summary with risk score (0-100) and risk level\n- Finding counts by severity (critical/high/medium/low/info)\n- Detailed findings grouped by severity with remediation steps\n- SOC 2 Trust Service Criteria compliance checklist (8 checks)\n\n## Pricing\n\n| Plan | Price | Includes |\n|------|-------|----------|\n| **Personal** | $19/mo | Single user, stdio transport, community support |\n| **Team** | $79/mo | Up to 10 users, HTTP transport, priority support, CI/CD integration guide |\n| **Enterprise** | $499/mo | Unlimited users, custom CVE feeds, SIEM integration, dedicated support, SLA |\n\nAll plans include access to the full CVE database with monthly updates.\n\n[Contact sales](mailto:sales@example.com) for enterprise trials and volume licensing.\n\n## Development\n\n```bash\n# Watch mode for development\nnpm run dev\n\n# Build\nnpm run build\n\n# Run with stdio\nnpm start\n\n# Run with HTTP transport\nnpm run start:http\n```\n\n## Architecture\n\n```\nsrc/\n  index.ts              Main server -- registers all tools, handles transport\n  types.ts              Shared TypeScript types for all modules\n  tools/\n    scan-config.ts      Config file scanner (secrets, permissions, transport, known vulns)\n    scan-tools.ts       Tool definition scanner (injection, poisoning, exfiltration)\n    check-cves.ts       CVE database lookup with semver matching\n    validate-auth.ts    Auth config validator (OAuth 2.1, API key, bearer)\n    report.ts           Report generator (risk score, findings, SOC 2 checklist)\n  data/\n    cve-database.ts     20 curated MCP CVE entries\n    patterns.ts         Detection signatures (secrets, injection, filesystem, commands)\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","homepage":"https://aivp-mcp.vercel.app","repository":{"type":"git","url":"git+https://github.com/vpatser1/mcp-servers.git","directory":"security-scanner"},"bugs":{"url":"https://github.com/vpatser1/mcp-servers/issues"}}