MCP Server Security Scan

Defensive security scan for Model Context Protocol (MCP) servers built with the official @modelcontextprotocol/sdk or mcp Python SDK. Detects tools exposing filesystem/shell with user-controlled paths, HTTP/SSE transports without authentication, unvalidated tool arguments, sensitive data leaking via resource URIs, and unbounded tool output that floods context. Invoke when the user asks to "review", "audit", or "scan" an MCP server implementation.

Dolphinllc eaf6eee 6.4 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/defensive/genai/mcp-server-security-scan commit eaf6eeec6a

Frequently asked questions

npx skillmds@latest add dolphinllc/mcp-server-security-scan