Mmcp.market

Securityscan MCP server

by securityscan-api·io.github.securityscan-api/securityscan·v0.2.0

Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout.

A89/100grade A
What users say
No reviews yet
Be the first
Safety scan
A89/100

full report

Adoption
New

0 stars16 downloads/wk

Reviews

Write one

Nobody has reviewed Securityscan yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Securityscan tools (8)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • audit_mcp_server_config

    Audit an MCP client configuration for security risks — works offline, no external service required. Detects: tool poisoning, hidden/coercive instructions in tool descriptions, hardcoded credentials, unpinned packages (rug-pull risk), insecure transport, and toxic capability combinations (shell + network, file-read + network).

  • check_dependencies

    Check the health of your agent's external dependencies: uptime, SSL validity, blacklist status, and a trust score 0-100 (DepScan).

  • full_stack_audit

    Complete security posture in one call: audits the MCP config, checks dependency health, analyzes an untrusted skill, scans the local network gateway, and scans any payload you're about to send out for secrets/PII — then correlates everything into a single prioritized report. Pass only what you have; each section is skipped gracefully if its input or service is missing.

  • network_scan

    Active security scan of a device or host with an autonomous AI agent that decides which follow-up probes to run (ActiveScanner). Only scan targets you own or have permission to test.

  • scan_secrets

    Scan a text payload (a prompt, an outbound API body, a file's contents) for secrets and PII BEFORE it leaves for an LLM or external API, and return a redacted copy. Catches the #1 real-world agent incident: secrets/PII leaking into a model's context.

  • scan_skill

    Analyze an AI agent skill for prompt injection, malware patterns, and OWASP LLM Top 10 issues BEFORE installing it (SecurityScan).

  • securityscan_checkout

    Start a Stripe checkout to buy a SecurityScan tier (agent-native sales). Returns a payment URL to hand to your user AND a PENDING API key that activates automatically once payment clears — no other setup step.

  • securityscan_pricing

    SecurityScan catalog: tiers, prices, quotas and the evidence behind the product — the fact sheet an agent needs to evaluate or recommend a purchase to its user. Fully offline, no API key required.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

no findings
  • Code scan5 source files scanned25/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 21 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10
Overall 89/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add securityscan -- uvx securityscan-mcp
Add to Cursor

Securityscan: common questions

Is Securityscan MCP server safe?
Yes, by our scan: it is graded A (89/100). Read the Securityscan safety report
How do I install Securityscan?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does Securityscan need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Securityscan maintained?
The last commit was 21 days ago (2026-08-30). The latest release is v0.2.0.
What can I use instead of Securityscan?
Servers from other publishers that do the same job: SkillTotal MCP server, Skillsmith MCP server and Bomly MCP server. Compare all Securityscan alternatives.

Alternatives to Securityscan

Same job from other publishers: the closest match first, then the best rated.

All Securityscan alternatives →
  • SkillTotal
    Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
    B
  • Skillsmith
    Share agent skills across your team, scan them for risk, and track what's actually used.
    B
  • Bomly
    Give your coding agent the dependency graph it is about to change: scan, diff, explain, audit
    B
  • mcptoon
    MCP tools + agent skills in one zero-dependency CLI: 71,929 -> 581 tokens (-99.2%, measured).
    A
  • Roast My Design System
    Audit your Design System and serve your Agent the rules that keep AI-written UI on-system.
    A

More from securityscan-api