mcp-scan

invariantlabs-ai
853
Constrain, log and scan your MCP connections for security vulnerabilities.
#agent #ai #mcp #modelcontextprotocol #security

Overview

mcp-scan Introduction

mcp-scan is a security scanning tool designed to statically and dynamically scan and monitor MCP connections for security vulnerabilities, including prompt injections, tool poisoning, and cross-origin escalations.

How to Use

To use mcp-scan, you can operate it in two modes: `mcp-scan scan` for static scanning of installed servers to detect malicious tool descriptions and `mcp-scan proxy` for real-time monitoring of MCP connections.

Key Features

Key features include scanning for various MCP client configurations, checking for prompt injection and tool poisoning attacks, enforcing guardrailing policies, and detecting PII and secrets in tool calls and responses.

Where to Use

mcp-scan can be used in any environment where MCP connections are established, particularly in software development, security auditing, and compliance monitoring.

Use Cases

Use cases for mcp-scan include securing development environments, monitoring production systems for vulnerabilities, and ensuring compliance with data protection regulations.

Content