MCPShield
Security scanner for MCP servers — detects tool poisoning, prompt injection, and 90+ vulnerability patterns
Install
Install and configure the MCP from https://github.com/MCPShield-Dev/mcpshield now. Follow the repository's installation instructions, ask me for anything you can't complete yourself, and verify its tools load.README
MCPShield CLI
Scan MCP servers and GitHub repositories for security vulnerabilities.
Powered by MCPShield — the MCP security scanner with 59+ detection rules covering the OWASP MCP Top 10.
Install
npm install -g mcpshield
Setup
Get a free API key at mcpshield.co/settings, then:
mcpshield auth mcp_sk_your_key_here
Usage
# Scan an HTTP MCP server
mcpshield scan --url https://mcp-server.example.com/mcp
# Scan a GitHub repository
mcpshield scan --github https://github.com/user/repo
# JSON output (for CI/CD)
mcpshield scan --url https://mcp-server.example.com/mcp --json
# Filter by severity
mcpshield scan --url https://mcp-server.example.com/mcp --severity high
Exit Codes
0— Scan completed, no critical findings1— Error (invalid key, rate limit, scan failure)2— Scan completed with critical findings
Environment Variables
MCPSHIELD_API_KEY— API key (alternative tomcpshield auth)MCPSHIELD_API_URL— Custom API endpoint (for self-hosted)
License
MIT
Related servers
Everythingmodelcontextprotocol91KReference / test server with prompts, resources, and toolsFetchmodelcontextprotocol91KWeb content fetching and conversion for efficient LLM usageFilesystemmodelcontextprotocol91KSecure file operations with configurable access controlsGitmodelcontextprotocol91KTools to read, search, and manipulate Git repositories
