mcp-scan / check a package
Check any MCP server package.
Run mcp-scan's scanners against any npm-published MCP server before you add it to a client config. Get a shareable report and a badge for its README.
What it checks
- Secrets and credentials leaked into server configs
- Prompt injection hidden in tool names or descriptions
- Supply-chain risk: typosquatting and low-trust packages