Skip to content

Add MCPSafe to /security — free pre-install scanner with 5-LLM consensus panel #2

Description

@mcpsafe-gh

Tool Submission: MCPSafe

Name: MCPSafe
URL: https://mcpsafe.io
Category: Pre-install scanner / Security
Suggested path: /security/tools/mcpsafe.mdx

What it does

MCPSafe is a free, no-account pre-install scanner for MCP servers. You give it a GitHub URL, npm package name, or PyPI package name, and it returns a security report before anything touches your environment.

It runs a 5-LLM consensus panel (Anthropic, Google, Mistral, OpenAI, Meta) to detect:

  • Tool poisoning — malicious instructions hidden in tool descriptions that manipulate LLM behavior
  • Hardcoded secrets — API keys, tokens, and credentials embedded in source
  • SSRF vulnerabilities — tools that can be directed to make unauthorized network requests
  • Overprivileged tool declarations — tools with broader access than their stated purpose requires

Results include an AIVSS score (0–10), per-finding breakdown with code locations, and an A–F grade. Scan completes in under 60 seconds for cached packages.

Why it belongs in /security

This is a distinct category from runtime gateways (MCP Manager, Lasso, etc.). Pre-install scanning happens before anything is connected — it's the check that prevents installing a server with critical issues in the first place.

Data from our analysis of 508 public MCP servers:

  • 22% had hardcoded credentials in source
  • 18% had tool poisoning vectors in tool descriptions
  • 23% had at least one critical-severity finding

Links

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions