Back to Browse

Scan MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.

About

Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.

Security Report

5.2
Moderate5.2Moderate Risk

mcp-scan is a well-architected security scanner for MCP servers with strong code quality, comprehensive OWASP MCP Top 10 coverage, and proper separation of concerns. Permissions align with its stated purpose (spawning stdio processes, making HTTP requests for scanning). Minor findings are low-severity code quality issues that do not materially impact security. Supply chain analysis found 5 known vulnerabilities in dependencies (2 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

process_spawn

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-codingselim-mcp-scan": {
      "args": [
        "-y",
        "owasp-mcp-scan"
      ],
      "command": "npx"
    }
  }
}

Reviews

No reviews yet

Be the first to review this server!

Scan MCP Server - Passive security scanner: audits MCP servers against the | MCP Marketplace