agent-security-scanner-mcp
AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.
npm · fingerprint 4f138c2592d663daafb99d5b · repository · RSS
23 tools
1 recorded versions
13h tracked
tracking started
What changed Nothing, since tracking began. That is the good outcome, and it is what most servers look like.
Current tools
Show all 23 tool fingerprints
check_package
5d874b25d88a56db
clawproof_health
5796e26a243e78cc
evaluate_compliance
0b25f3c74153d215
fix_security
d734c6cf730218d4
get_compliance_controls
7f192ad5196abdd4
list_package_stats
682fc7b493dcad82
list_security_rules
206fc7331d04e4df
record_security_outcome
98080d8d02f5a48d
sbom_check_hallucinations
0d7a40a7ab1aeca5
sbom_diff
297e6c6a28aba59e
sbom_export_report
a94ad2f0e3ba51e9
sbom_generate
67b52c95739267b4
sbom_scan_vulnerabilities
ee30b93243651e6d
scan_agent_action
06da99339a596777
scan_agent_prompt
387a6b4852606dbf
scan_git_diff
9822db896fa40939
scan_mcp_server
fe76327fd3cd4bdd
scan_packages
c31267588b672048
scan_project
5db5a51fcd693e3c
scan_security
071af8366aa9d513
scan_skill
01885d832772233e
scanner_health
fc9cc9e8383bdab2
score_aivss
cff3b0bdedc0eb85
Watch this server yourself
If you run this server, put the proxy in front of it. It pins these exact
fingerprints on first connect and stops the session if they move.
npx --yes mcp-pin@0.1.0 -- <your agent-security-scanner-mcp command>
Or subscribe to this page's RSS feed
to be told when it changes.
Badge
The badge states one fact about time and nothing else. It never claims a
server is safe.
[](https://mcp-pin.gautamkhosla.com/servers/3b724de421632f29.html)
mcp-pin keeps a public, append-only record of MCP tool definitions. Every entry is hash linked and every head is signed, so you can download the log and check it yourself with npx --yes mcp-pin@0.1.0 verify-log. You do not have to trust whoever runs this.
Crawling is one tools/list per server per day. No tool is ever called. To opt out, add your server to OPTOUT.txt or open an issue. Honoured on the next crawl, no justification needed.
Run by Gautam Khosla as an independent open-source project. Not affiliated with
Anthropic, the Model Context Protocol project, or any server listed here.
About this project, and how to contact me .
MIT licensed. Source on GitHub .