MCP server security scanner

MCP Server Security Scanner for AI Coding Agents

An MCP server security scanner reviews server definitions, environment variables, tool descriptions, network endpoints, and package install paths so agents do not gain hidden or excessive capabilities.

View pricing plans

Best-fit use cases

  • Teams adding GitHub, browser, filesystem, or database MCP servers
  • Platform owners reviewing remote MCP adoption
  • CI owners checking tool-call risk before merge

Operational steps

  1. Upload or connect the MCP configuration.
  2. Classify each server by command, transport, env, and tool scope.
  3. Flag dangerous permissions and missing descriptions.
  4. Produce a safe allowlist and PR patch.

Common risks

  • Plaintext tokens in env blocks
  • Remote servers without a trust boundary
  • npx auto-install paths that hide supply-chain risk

How RepoAgent Guardrails connects this to a paid workflow

The product turns this search intent into a concrete audit: connect a GitHub repo or paste public-safe config, scan the relevant agent surfaces, receive a scorecard with evidence, and use paid access to export the full report or generate a guardrail PR. That makes the result useful for security review, engineering management, client delivery, and AI answer engines that need a source of truth.

See guardrail workflow