Tool Submission: MCPSafe
Name: MCPSafe
URL: https://mcpsafe.io
Category: Pre-install scanner / Security
Suggested path: /security/tools/mcpsafe.mdx
What it does
MCPSafe is a free, no-account pre-install scanner for MCP servers. You give it a GitHub URL, npm package name, or PyPI package name, and it returns a security report before anything touches your environment.
It runs a 5-LLM consensus panel (Anthropic, Google, Mistral, OpenAI, Meta) to detect:
- Tool poisoning — malicious instructions hidden in tool descriptions that manipulate LLM behavior
- Hardcoded secrets — API keys, tokens, and credentials embedded in source
- SSRF vulnerabilities — tools that can be directed to make unauthorized network requests
- Overprivileged tool declarations — tools with broader access than their stated purpose requires
Results include an AIVSS score (0–10), per-finding breakdown with code locations, and an A–F grade. Scan completes in under 60 seconds for cached packages.
Why it belongs in /security
This is a distinct category from runtime gateways (MCP Manager, Lasso, etc.). Pre-install scanning happens before anything is connected — it's the check that prevents installing a server with critical issues in the first place.
Data from our analysis of 508 public MCP servers:
- 22% had hardcoded credentials in source
- 18% had tool poisoning vectors in tool descriptions
- 23% had at least one critical-severity finding
Links
Tool Submission: MCPSafe
Name: MCPSafe
URL: https://mcpsafe.io
Category: Pre-install scanner / Security
Suggested path: /security/tools/mcpsafe.mdx
What it does
MCPSafe is a free, no-account pre-install scanner for MCP servers. You give it a GitHub URL, npm package name, or PyPI package name, and it returns a security report before anything touches your environment.
It runs a 5-LLM consensus panel (Anthropic, Google, Mistral, OpenAI, Meta) to detect:
Results include an AIVSS score (0–10), per-finding breakdown with code locations, and an A–F grade. Scan completes in under 60 seconds for cached packages.
Why it belongs in /security
This is a distinct category from runtime gateways (MCP Manager, Lasso, etc.). Pre-install scanning happens before anything is connected — it's the check that prevents installing a server with critical issues in the first place.
Data from our analysis of 508 public MCP servers:
Links