Dfx Mcp Scanner
FreeNot checkedSecurity scanner for MCP (Model Context Protocol) servers. Detect malicious tools, data exfiltration, and supply chain risks.
About
Security scanner for MCP (Model Context Protocol) servers. Detect malicious tools, data exfiltration, and supply chain risks.
README
Security scanner for MCP (Model Context Protocol) servers. Detect malicious tools, data exfiltration, and supply chain risks before connecting an MCP server to your AI agent.
PyPI Python 3.10+ License: MIT CI
Why MCP Scanner?
MCP servers give AI agents (Claude Code, Cursor, Copilot) direct access to tools, filesystems, and APIs. But nobody is checking if those servers are safe.
MCP Scanner analyzes:
- MCP server config files (Claude Code, Cursor, generic)
- Command-level risks (
npx --yes,curl|bash,sudo) - Secret exposure in environment variables
- Filesystem and network access patterns
- Source code of MCP server implementations (with AgentGuard integration)
Quick Start
pip install dfx-mcp-scanner
# Scan your Claude Code MCP config
mcp-scanner
# Scan a specific config
mcp-scanner ~/.cursor/mcp.json
# JSON output
mcp-scanner .mcp.json --format json
What It Detects
| Rule | Severity | Description |
|---|---|---|
| Remote code execution | CRITICAL | `curl |
| Auto-install packages | HIGH | npx --yes without version pinning |
| Privileged execution | CRITICAL | Server running as root/sudo |
| Secret exposure | CRITICAL | Real API keys/tokens in config env vars |
| Host filesystem access | HIGH | Server accessing /etc, /root, /proc |
| External network access | MEDIUM | Server connecting to non-localhost URLs |
| Excessive tool count | LOW | Server registering >20 tools |
Supported Configs
- Claude Code (
~/.claude/claude_code_config.json) - Cursor (
~/.cursor/mcp.json) - Project-level (
.mcp.json) - Generic MCP server configs
AgentGuard Integration
When AgentGuard is installed, MCP Scanner performs deep source code analysis on MCP server implementations using all 10 OWASP ASI detection rules.
License
MIT - see LICENSE.
Built by Dockfix Labs.
AgentGuard Ecosystem
AgentGuard is the core security scanner. Companion tools:
| Tool | Purpose | Install |
|---|---|---|
| agentguard | AI agent code security scanner | pip install dfx-agentguard |
| mcp-scanner | MCP server security audit | pip install dfx-mcp-scanner |
| agentguard-app | GitHub App for PR reviews | Install from Marketplace |
| agentguard-vscode | VS Code inline diagnostics | Install from VS Code |
| agentguard-benchmark | Detection benchmark suite | git clone |
| agentguard-demo | Live demo with Code Scanning | git clone |
19 detection rules | 102 tests | 50 benchmark samples | OWASP ASI Top 10 GitHub Action: dockfixlabs/agentguard@v1
Installing Dfx Mcp Scanner
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/dockfixlabs/mcp-scannerFAQ
Is Dfx Mcp Scanner MCP free?
Yes, Dfx Mcp Scanner MCP is free — one-click install via Unyly at no cost.
Does Dfx Mcp Scanner need an API key?
No, Dfx Mcp Scanner runs without API keys or environment variables.
Is Dfx Mcp Scanner hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Dfx Mcp Scanner in Claude Desktop, Claude Code or Cursor?
Open Dfx Mcp Scanner on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Fetch
Web content fetching and conversion for efficient LLM usage.
AWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
by modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
by xuzexin-hzCompare Dfx Mcp Scanner with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All ai MCPs
