Skip to main content

mcp-scan / check a package

Check any MCP server package.

Run mcp-scan's scanners against any npm-published MCP server before you add it to a client config. Get a shareable report and a badge for its README.

Try one

What it checks

  • Secrets and credentials leaked into server configs
  • Prompt injection hidden in tool names or descriptions
  • Supply-chain risk: typosquatting and low-trust packages