mcp-scan is a Model Context Protocol (MCP) server: Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F. In practice that means any MCP-compatible AI assistant can call mcp-scan's tools directly — the model decides when to use them in a conversation or agent run.
It runs locally: the npm package owasp-mcp-scan speaks MCP over stdio on your machine. No credentials are required — it works out of the box. The current release is v0.2.1, published under the MIT license, with source at CodingSelim/mcp-scan on GitHub.
mcp-scan is listed under Security on mcp.site and works with any MCP client — Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Zed and the rest of the ecosystem — using the install snippets below. If you maintain mcp-scan for CodingSelim, claim this listing to verify ownership, earn the Verified badge, and keep the details current.