AgentStack
MCP unreviewed MIT Self-run

Mcp Scanner

mcp-dockfixlabs-mcp-scanner · by dockfixlabs

Security scanner for MCP (Model Context Protocol) servers - detects malicious tools, data exfiltration, and supply chain risks before connecting to your AI agent.

No reviews yet
0 installs
3 views
0.0% view→install

Install

$ agentstack add mcp-dockfixlabs-mcp-scanner

Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Mcp Scanner? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

MCP Scanner

> Security scanner for MCP (Model Context Protocol) servers. Detect malicious tools, data exfiltration, and supply chain risks before connecting an MCP server to your AI agent.

[](https://pypi.org/project/dfx-mcp-scanner/) [](https://python.org) [](LICENSE) [](https://github.com/dockfixlabs/mcp-scanner/actions)


Why MCP Scanner?

MCP servers give AI agents (Claude Code, Cursor, Copilot) direct access to tools, filesystems, and APIs. But nobody is checking if those servers are safe.

MCP Scanner analyzes:

  • MCP server config files (Claude Code, Cursor, generic)
  • Command-level risks (npx --yes, curl|bash, sudo)
  • Secret exposure in environment variables
  • Filesystem and network access patterns
  • Source code of MCP server implementations (with AgentGuard integration)

Quick Start

pip install dfx-mcp-scanner

# Scan your Claude Code MCP config
mcp-scanner

# Scan a specific config
mcp-scanner ~/.cursor/mcp.json

# JSON output
mcp-scanner .mcp.json --format json

What It Detects

| Rule | Severity | Description | |------|----------|-------------| | Remote code execution | CRITICAL | curl | bash patterns in server startup | | Auto-install packages | HIGH | npx --yes without version pinning | | Privileged execution | CRITICAL | Server running as root/sudo | | Secret exposure | CRITICAL | Real API keys/tokens in config env vars | | Host filesystem access | HIGH | Server accessing /etc, /root, /proc | | External network access | MEDIUM | Server connecting to non-localhost URLs | | Excessive tool count | LOW | Server registering >20 tools |

Supported Configs

  • Claude Code (~/.claude/claude_code_config.json)
  • Cursor (~/.cursor/mcp.json)
  • Project-level (.mcp.json)
  • Generic MCP server configs

AgentGuard Integration

When AgentGuard is installed, MCP Scanner performs deep source code analysis on MCP server implementations using all 10 OWASP ASI detection rules.

License

MIT - see [LICENSE](LICENSE).


Built by Dockfix Labs.


AgentGuard Ecosystem

AgentGuard is the core security scanner. Companion tools:

| Tool | Purpose | Install | |------|---------|---------| | agentguard | AI agent code security scanner | pip install dfx-agentguard | | mcp-scanner | MCP server security audit | pip install dfx-mcp-scanner | | agentguard-app | GitHub App for PR reviews | Install from Marketplace | | agentguard-vscode | VS Code inline diagnostics | Install from VS Code | | agentguard-benchmark | Detection benchmark suite | git clone | | agentguard-demo | Live demo with Code Scanning | git clone |

19 detection rules | 102 tests | 50 benchmark samples | OWASP ASI Top 10 GitHub Action: dockfixlabs/agentguard@v1

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.