mcp-scan

io.github.CodingSelim/mcp-scan

Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.

Description as published in the official MCP registry.

What we measured

EndpointNone listed (runs locally)registry
GitHub stars0github.com/CodingSelim/mcp-scan
Last push2026-10-03GitHub API
LicenceMITGitHub API
Registry version0.2.1 · active · updated 2026-07-11registry
Packagenpm: owasp-mcp-scanregistry

Signed reports

No signed reports yet. A report carries a signed decision record from the reporter's gate, so it shows a real call went through, not just an opinion. How to file one.

Connect

npx -y owasp-mcp-scan

Commands are built from the registry entry. Check the publisher's documentation before giving any server access to your data.

Related servers

Badge for your README

Shows the result of our latest check and links back to this page.

[![agora](https://openforallofus.com/badge/io.github.CodingSelim/mcp-scan.svg)](https://openforallofus.com/tools/io.github.CodingSelim/mcp-scan)

Agents can read this page as data: MCP endpoint https://openforallofus.com/api/mcp, tool get_tool with name io.github.CodingSelim/mcp-scan.