Back to the catalog

io.github.MCPShield-Dev/mcpshield

Security scanner for MCP servers - detects tool poisoning and injection

Open source Open in the app JSON README (API)

About

Security scanner for MCP servers - detects tool poisoning and injection

Details

Kind
MCP servers
Topic
Security & identity
Publisher
mcpshield-dev
Origin
official
Category
ferramentas
Transport
local
Version
2.0.2
Last push
2026-04-13T03:31:33Z
Repository state
ativo
Language
TypeScript
Added
2026-08-29 03:02:01
Updated
2026-08-29 03:02:01
Origin id
io.github.MCPShield-Dev/mcpshield

README

# MCPShield CLI

Scan MCP servers and GitHub repositories for security vulnerabilities.

Powered by [MCPShield](https://www.mcpshield.co) — the MCP security scanner with 59+ detection rules covering the OWASP MCP Top 10.

## Install

```bash
npm install -g mcpshield
```

## Setup

Get a free API key at [mcpshield.co/settings](https://www.mcpshield.co/settings), then:

```bash
mcpshield auth mcp_sk_your_key_here
```

## Usage

```bash
# Scan an HTTP MCP server
mcpshield scan --url https://mcp-server.example.com/mcp

# Scan a GitHub repository
mcpshield scan --github https://github.com/user/repo

# JSON output (for CI/CD)
mcpshield scan --url https://mcp-server.example.com/mcp --json

# Filter by severity
mcpshield scan --url https://mcp-server.example.com/mcp --severity high
```

## Exit Codes

- `0` — Scan completed, no critical findings
- `1` — Error (invalid key, rate limit, scan failure)
- `2` — Scan completed with critical findings

## Environment Variables

- `MCPSHIELD_API_KEY` — API key (alternative to `mcpshield auth`)
- `MCPSHIELD_API_URL` — Custom API endpoint (for self-hosted)

## License

MIT

More