Scan MCP servers for security findings before connecting them to agents with MCP Scanner
Run MCP Scanner against a remote or local MCP server before trusting it, so the agent gets a bounded security review of tools, prompts, resources, dependencies, and supply-chain risk.
Prerequisites
Python 3.11+, uv, optional Cisco AI Defense API key, optional LLM provider key, optional VirusTotal API key
Installation
Choose whichever fits your setup:
- Copy this skill folder into your local skills directory.
- Clone the repo and symlink or copy the skill into your agent workspace.
- Add the repo as a git submodule if you manage shared skills centrally.
- Install it through your internal provisioning or packaging workflow.
- Download the folder directly from GitHub and place it in your skills collection.
Install command or upstream instructions:
Install with uv: uv tool install --python 3.13 cisco-ai-mcp-scanner