Open-Source Tool mcp-security-scan Helps Teams Audit AI Agent MCP Servers
MCP (Model Context Protocol) servers act as intermediaries between large language models and external tools, giving them broad system access and making them a high-value security target. Despite this, most development teams deploy MCP servers without any formal security review, a gap that contributed to the Moltbook breach, which exposed 35,000 emails and 1.5 million API tokens. An open-source CLI tool called mcp-security-scan has been released under the MIT license to address this problem, scanning MCP server source code and runtime behavior for risks including credential theft, data exfiltration, unsafe code execution, and filesystem vulnerabilities. The tool generates a structured JSON report and assigns a 0-100 trust score, with high-severity findings deducting 15 points each, and integrates with AgentGraph's identity layer. It is available as both a command-line tool and a GitHub Action at github.com/agentgraph-co/mcp-security-scan.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in