Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.
Stars
14
Forks
0
Watchers
14
Open Issues
0
Overall repository health assessment
^1.0.0^1.10.0^6.0.0No contributors data available
feat: add census-2026 research paper — Weaponized by Design
a147550View on GitHubfeat: add deobfuscation layer and toxic data flow detection
ee87524View on GitHubfeat: supply chain audit — --audit flag checks deps for known vulns and malicious packages
0adbe59View on GitHubfix: update scanner links from /scanner to /docs (route doesn't exist)
dfd51c8View on GitHubfeat: scanner CLI upgrades — evidence field, policy generation, HTML report
3332d5bView on GitHubdocs: add human-in-the-loop bypass finding to PoC section
ba63b95View on GitHubdocs: add end-to-end injection PoC — confirmed successful (2026-03-31)
179c34bView on GitHubdocs: expand to industry-wide analysis with CVEs and 5-framework comparison
09df644View on GitHubdocs: deepen agent-teams paper with live PoC results and concrete fixes
b7bf171View on GitHubdocs: update agent-teams paper with live behavioral evidence
629370dView on GitHubdocs: publish The Multi-Agent Auth Gap research paper
b142ee8View on GitHubchore: add .npmignore to exclude reports, data, test files from npm package
27973a9View on GitHubdocs: publish State of MCP Server Security 2026 whitepaper
82ba18cView on GitHub