Show HN Launch Pro at €19/mo this week only — normally €29/mo. HN founding rate locked for life.  Claim €19/mo rate →
MCP Server Security Scanner
Show HN — April 8, 2026

MCP Security Audit — automated & manual

Know what you're installing. Scan any MCP server in 60 seconds and get a professional security report with scores, findings, and remediation steps.

See a sample report →
Paste any public GitHub repository URL.
200+ servers scanned · 11 servers with critical/high findings · Avg score: 90.5/100 · View leaderboard
Scanned servers from GitHub Google Microsoft Cloudflare Supabase Vercel
Shipping MCP servers to production? Free 30-min threat model → No pitch · 3 slots left this week

Permission Scope Analysis

Understand what filesystem, network, and shell access the server requests. Know your exposure before you install.

Vulnerability Detection

Automated pattern matching for shell injection, SSRF, path traversal, eval usage, hardcoded secrets, and more.

Supply Chain Review

Dependency count, known compromised packages, lockfile presence, and install script detection.

Shareable Reports

Professional HTML reports scored 0 to 100. Share with your team, attach to pull requests, include in security reviews.

Server Comparison

Compare two MCP servers side by side. See which one is safer across every category before you choose.

CI/CD Integration

Add to GitHub Actions in 2 minutes. Automatically scan on every PR and block merges that fail security checks.

Security Badge

Embed an auto-updating security score badge in your README. Show users your server passes mcp-audit.

Python, Go, Rust & JS

Full static analysis across all major MCP server languages. Catches eval, shell injection, pickle attacks, unsafe blocks, and more.

Server Directory

Browse all scanned servers with search and filters. Find the safest MCP servers for your project.

Embeddable Widget

Add a rich score card to your docs or website. More than a badge — shows score ring, status, and links to the full report.

Claim Your Server

Verify ownership of your MCP server. Get email alerts when your security score changes and a verified badge.

Webhook Notifications

Register webhooks via the API to get notified when scans complete. Integrate with Slack, Discord, or your own systems.

What 200+ scans revealed

Real data from scanning the most popular MCP servers on GitHub.

90.5
Average security score
11
Servers with critical/high findings
47%
Servers requesting shell access
23%
Servers with eval() or dynamic code

Data from the leaderboard. Updated weekly. Read the full report.

What scanners are finding

"Ran mcp-audit on our 4 internal MCP servers. Found an eval() call processing user input that our code review missed. Fixed in 10 minutes."
-- Security engineer, Series B startup
"We scanned 12 MCP servers before adding them to our Claude setup. 3 had shell access we didn't know about. The report made it easy to justify blocking them."
-- DevOps lead, fintech company
"Added the GitHub Action to our CI pipeline. Now every PR that adds an MCP server gets automatic security scoring. Takes 30 seconds per scan."
-- Platform engineer, enterprise SaaS

Built for teams that run MCP security audits

Whether you're evaluating third-party servers or shipping your own, mcp-audit fits your workflow.

Security engineers

Evaluate every MCP server before it touches production. Get structured findings you can drop into your security review or compliance report.

MCP server developers

Scan your server before publishing. Fix findings before users file issues. Display the security badge to build trust with your users.

AI-forward companies

Running Claude, GPT-4, or Gemini with MCP tools? Know exactly what filesystem, network, and shell access each server requests before it goes live.

How it works

1

Paste a URL

Enter the GitHub URL of any public MCP server repository.

2

The code gets analyzed

The scanner fetches the source, dependencies, and metadata. No AI involved. Deterministic, reproducible analysis.

3

Get your report

Receive a scored security report with specific findings and remediation guidance.

Sample report preview
View full report →
85
github/github-mcp-server
Score: 85/100 · Grade: B+ · 3 findings
HIGH Shell command execution via child_process.exec()
MEDIUM No input schema validation on 2 tools
LOW Missing lockfile (package-lock.json not found)
Pro users get all findings + remediation steps Upgrade to Pro →

Recent scans

Live feed of servers being scanned right now.

Loading recent scans...
Free — 10 slots/month

Book a free 30-min MCP security review

Shipping production AI agents? I’ll review your MCP setup live, map your 3 highest-risk vectors, and show you how to validate each one. No sales pitch.

  • Tool poisoning & prompt injection paths in your stack
  • Permission scope gaps your security team will flag
  • Written findings summary delivered same day
Book a free security review → See sample audit report →
You get
3 prioritized findings + remediation steps, written up same day.
Why free?
Real findings sharpen mcp-audit’s detection. I gain; you gain.
Show HN Founding Rate — Expires April 18
--
days
:
--
hours
:
--
mins
:
--
secs

€19/mo, locked for life

HN community rate: €19/mo forever — regular price is €29/mo. First 50 subscribers. Expires when we take this down.

47 of 50 spots remaining
Cancel any time. No lock-in.

No credit card · API key in inbox instantly · 7 days free, then €19/mo

Pricing

Start scanning for free. Upgrade when you need more.

Feature Free Pro Team Manual Audit
Scans per day 1 Unlimited Unlimited + API N/A
Findings shown Top 3 All All All + custom
Remediation guidance -- Yes Yes Expert-written
CI/CD integration -- API access API + webhooks --
PDF / compliance export -- Yes Yes Board-ready
Private repos -- -- -- Yes
OWASP MCP Top 10 Basic Full Full Full + threat model
Free
€0
  • 1 scan per day
  • Overall score + top 3 findings
  • Shareable report link
  • Leaderboard access
Pro Show HN Rate
€29/mo regular Expires April 18
Save 17%
€19 / mo
  • Unlimited scans
  • Full reports with all findings
  • Step-by-step remediation guidance
  • "Audited by Pyfio" trust badge
  • PDF export for compliance
  • API access for CI/CD integration
  • Priority support
Start Free Trial — then €19/mo →

HN founding rate — €19/mo locked for life. Cancel any time.

⚡ Show HN special — loading spots…

Teams
Team
€99 / mo
  • Everything in Pro
  • Up to 10 team members
  • Shared scan history & dashboard
  • 2,000 API scans / month
  • Slack & webhook notifications
  • Organization-wide security policy
  • Dedicated onboarding call
Get Team Access →

Includes onboarding call. Annual billing available (2 months free).

High-ticket
Manual Audit
€2,500 one-time
  • Full manual code review by a human
  • Internal & private repositories
  • OWASP MCP Top 10 coverage
  • Custom threat model for your stack
  • Remediation roadmap with priority order
  • Compliance-ready PDF report
  • 3-day turnaround guaranteed
Request Audit →

Fixed price. Delivered in 3 business days. No scope creep.

No credit card required
Cancel anytime
GDPR compliant (DE)
Stripe-secured payments

Questions? hello@pyfio.com

Need team or enterprise access?

Unlimited seats, private scan history, SSO, and custom SLA. Email us for a custom quote.

Custom Engagements

Need a full security audit or custom MCP build?

The automated scanner covers 90% of cases. For the rest — internal servers, compliance requirements, or building MCP tooling from scratch — I do custom work.

MCP Security Audit €2,500 fixed · 48h delivery
Custom MCP Build €8,000 fixed · 5 days
Enterprise / Day rate €800 / day

⚡ Flash offer: 3 audit slots left · April 8–18 only

Claim audit slot →

Reply within 2 hours. Fixed price, no surprises. Delivered in 48h or free.

Proof of delivery
mcp-audit scanner
Scanned 200+ MCP servers. Found eval() abuse, SSRF vectors, and supply chain issues that wouldn't show up in a code review.
Agent Upgrade Feed
8-stage automated pipeline running weekly. Aggregates, vets, scores, and publishes — zero manual intervention.
Full services overview with packages →
Enterprise
For teams shipping MCP servers to production

MCP Security Program
Ongoing coverage, not a one-time scan

Your MCP servers change every sprint. A one-time audit has a 30-day shelf life. The Security Program keeps you covered: monthly re-audits, CVE response within 48h, and a compliance trail your security team can hand to auditors.

One-time Audit
€8,000–€15,000
Full stack review, board-ready report. Scope-dependent.
Annual Retainer
€25,000–€60,000
Monthly re-audits + 48h CVE response + quarterly board report.
Enterprise Program
€60,000–€120,000
>10 MCP servers, multi-team. Includes developer training.
Request a security briefing →
20-minute call to walk through findings in your stack. No pitch deck.
Initial audit of all MCP servers in your stack
Monthly re-audits as servers are updated
48h CVE response SLA
Quarterly board-level report
Developer training session (1×/quarter)

Frequently Asked Questions

Why should I scan MCP servers before installing them?+

MCP servers run with significant permissions inside your AI agent setup. A malicious or poorly-written server can exfiltrate data, execute shell commands, or poison your agent's tool context. Scanning before installing takes 60 seconds and can prevent a breach that takes weeks to clean up.

What does the scanner actually check?+

Five categories: (1) Permission scope -- filesystem, network, shell, and environment access. (2) Code safety -- eval(), SSRF, path traversal, hardcoded secrets. (3) Supply chain -- dependency count, lockfiles, known compromised packages, install scripts. (4) Transparency -- LICENSE, README, description quality. (5) Maintenance -- recent commits, open issues, activity signals.

Is this an AI-based scanner?+

No. The analysis is deterministic static analysis -- pattern matching against known vulnerability signatures. No LLMs involved in the scan. This means results are reproducible and auditable, not probabilistic.

What is tool poisoning?+

Tool poisoning is when malicious instructions are hidden in MCP tool names or descriptions. When your AI agent reads these descriptions to decide which tool to call, it may execute unintended actions -- data exfiltration, privilege escalation, or overriding user instructions. This is the #1 MCP-specific attack vector.

Can I scan private repositories?+

The free scanner works with public GitHub repositories. For private repos, internal servers, or on-premise deployments, book a manual security audit starting at EUR 2,500. Contact us for details.

How does pricing work?+

Free: 1 scan per day, top 3 findings shown. Pro (EUR 19/mo founding rate): unlimited scans, all findings with remediation, PDF export, API access for CI/CD. Team (EUR 99/mo): up to 10 members, shared dashboard, Slack notifications. Manual Audit: EUR 2,500 one-time for full human review.

Impressum
Pyfio UG (haftungsbeschränkt) i.G.
Andreas Tissen
Haferweg 30b, 29614 Soltau, Germany
Shipping MCP servers to production? 3 slots left
Free threat model →