MCP servers hand tools and prompts directly to LLM agents — most have never been audited. scan-my-mcp connects to any MCP server, enumerates everything it exposes, and runs 6 security checks: secret exposure, auth enforcement, dangerous permissions, input validation, prompt injection, and context-window cost. Every finding includes the exact location and a fix. Try it instantly at mcpscanner.yxsh.in or install CLI tool for local MCPs.
Scan My MCP is a SaaS tool that audits MCP servers for security vulnerabilities by connecting to any MCP server and performing six security checks. It provides detailed findings, including exact locations and suggested fixes for issues such as secret exposure and prompt injection.