MCP Security Tools
Free static security analyzers for MCP configurations, tool definitions and external content. Review dangerous permissions, leaked credentials, command execution, prompt injection and network-request risks.
MCP Permission Checker
Review filesystem, network, shell and credential permissions.
SecurityMCP Secret Scanner
Find hard-coded tokens, passwords and private credentials.
SecurityMCP Tool Risk Scanner
Analyze tool definitions for dangerous capabilities.
SecurityMCP Prompt Injection Checker
Detect suspicious instructions and prompt-injection patterns.
SecurityMCP SSRF Checker
Find localhost, metadata and private-network URL risks.
SecurityMCP Command Execution Checker
Detect dangerous shells and command-execution patterns.
SecurityMCP External $ref Scanner
Find external schema references without fetching remote content.
Why MCP security needs multiple checks
An MCP integration can connect an AI application to local files, operating-system commands, APIs, remote services and credentials. Security therefore depends on more than one configuration field.
Permission review helps identify excessive access. Secret scanning finds credentials embedded in shared configuration. Prompt-injection analysis reviews untrusted content, while SSRF and command-execution checks focus on network and operating-system impact.
These tools perform static analysis. They do not prove that an MCP server is secure and do not replace source review, runtime testing or environment-specific controls.