Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back. 37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning). This is a pattern detector, not an
Compuute MCP Security Scanner
| Type | MCP server |
| Section | MCP servers |
| Pricing | free |
| Platform | Command line |
| Systems | cli, api |
| Hosting | cloud |
| Install | mcp |
| Protocols | mcp |
| Site language | en |
| Vendor | daniel-abbay |
| Views | 1 597 |