{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_nckxj3w2avvd","handle":"jaimenbell-mcp-security-scanner","url":"https://wellknown.network/agents/jaimenbell-mcp-security-scanner","links":{"self":"https://wellknown.network/agents/jaimenbell-mcp-security-scanner/record.json","html":"https://wellknown.network/agents/jaimenbell-mcp-security-scanner","markdown":"https://wellknown.network/agents/jaimenbell-mcp-security-scanner/record.md","api":"https://wellknown.network/api/v1/agents/jaimenbell-mcp-security-scanner","status":"https://wellknown.network/api/v1/agents/jaimenbell-mcp-security-scanner/status","claim":"https://wellknown.network/agents/jaimenbell-mcp-security-scanner/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/jaimenbell-mcp-security-scanner/claim.json","badge":"https://wellknown.network/agents/jaimenbell-mcp-security-scanner/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/jaimenbell-mcp-security-scanner/history","tools":"https://wellknown.network/api/v1/agents/jaimenbell-mcp-security-scanner/tools"},"ard":{"identifier":"urn:air::server:jaimenbell-mcp-security-scanner","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"jaimenbell-mcp-security-scanner","summary":"Static security scanner for MCP servers — codegen injection, tool-param injection, auth posture, secret handling.","description":"# mcp-security-scanner \n \n[![CI](https://github.com/jaimenbell/mcp-security-scanner/actions/workflows/ci.yml/badge.svg)](https://github.com/jaimenbell/mcp-security-scanner/actions/workflows/ci.yml) \n \nA static security scanner for [Model Context Protocol](https://modelcontextprotocol.io) servers. Point it at an MCP server repo; it reads the source and flags the vulnerability classes that actually show up in production MCP servers — with a severity, a `file:line`, a remediation, and an honest **confidence** on every finding. \n \n> [!info] What this is, plainly \n> This is **static analysis**, not a prover. It reads code; it does not run your server, and it does not prove any finding is remotely exploitable. It produces a prioritized review queue, not a verdict. A \"clean bill\" means *these detectors found no critical/high patterns* — not a security guarantee. That boundary is printed on every report on purpose. \n \n> [!warning] Not to be confused with the other PyPI package named `mcp-security-scanner` \n> There is an unrelated project on PyPI under the plain name `mcp-security-scanner` (a runtime pentester that connects to a *live* MCP server over HTTP/SSE). This repo is a different tool: it performs **static analysis of server source code**, offline, with no network connection to the target. Because the plain name was already taken, this project's PyPI distribution is published as `jaimenbell-mcp-security-scanner`; the console command (`mcp-scan`) and the import package (`mcp_scanner`) are unaffected. \n \n## What it scans \n \nSeven detector families. The first six are grounded in a real finding from a fleet-wide audit of production MCP servers; the seventh (added 2026-07-21) covers scheduled jobs, wrappers, and IaC/CI files — cron, systemd, GitHub Actions, PowerShell/bash/batch deploy scripts: \n \n| # | Class | Detects | \n|---|---|---| \n| 1 | **Codegen / template injection** | Jinja `autoescape` off in a code-*generating* tool that renders untrusted fields into generated …","publisher":{"name":"Jaime Bell","url":null},"homepage":"https://github.com/jaimenbell/mcp-security-scanner","repository":"https://github.com/jaimenbell/mcp-security-scanner/releases","version":"0.3.1","license":"MIT","protocols":["mcp"],"tags":["mcp","model-context-protocol","security","static-analysis","sast"],"pricing":null,"endpoints":[{"url":"pypi:jaimenbell-mcp-security-scanner","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi","publisherName":"pypi"}},"derived":{"capabilities":[{"slug":"code.security-review","name":"Security Review","confidence":1,"provenance":"declared"},{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":1,"provenance":"derived"},{"slug":"security.scanning","name":"Security Scanning","confidence":1,"provenance":"derived"},{"slug":"dev.package-management","name":"Packages & Dependencies","confidence":0.768,"provenance":"derived"}],"categories":["code","dev","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"jaimenbell-mcp-security-scanner","registry":"pypi","observedAt":"2026-09-15T21:22:09.535Z","publishedAt":"2026-07-31T17:00:03.154470Z","latestVersion":"0.3.1"},"toolSurface":null,"endpointFacts":[]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"jaimenbell-mcp-security-scanner","url":"https://pypi.org/project/jaimenbell-mcp-security-scanner/","firstSeenAt":"2026-09-09T22:22:14.873Z","fetchedAt":"2026-09-15T21:20:35.948Z","normalizedAt":"2026-09-15T21:20:35.948Z"}]},"firstSeenAt":"2026-09-09T22:22:14.873Z","updatedAt":"2026-09-15T21:22:09.535Z"}