io.github.MCPShield-Dev/mcpshield
Security scanner for MCP servers - detects tool poisoning and injection
Open source Open in the app JSON README (API)
About
Security scanner for MCP servers - detects tool poisoning and injection
Details
- Kind
- MCP servers
- Topic
- Security & identity
- Publisher
- mcpshield-dev
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 2.0.2
- Last push
- 2026-04-13T03:31:33Z
- Repository state
- ativo
- Language
- TypeScript
- Added
- 2026-08-29 03:02:01
- Updated
- 2026-08-29 03:02:01
- Origin id
io.github.MCPShield-Dev/mcpshield
README
# MCPShield CLI Scan MCP servers and GitHub repositories for security vulnerabilities. Powered by [MCPShield](https://www.mcpshield.co) — the MCP security scanner with 59+ detection rules covering the OWASP MCP Top 10. ## Install ```bash npm install -g mcpshield ``` ## Setup Get a free API key at [mcpshield.co/settings](https://www.mcpshield.co/settings), then: ```bash mcpshield auth mcp_sk_your_key_here ``` ## Usage ```bash # Scan an HTTP MCP server mcpshield scan --url https://mcp-server.example.com/mcp # Scan a GitHub repository mcpshield scan --github https://github.com/user/repo # JSON output (for CI/CD) mcpshield scan --url https://mcp-server.example.com/mcp --json # Filter by severity mcpshield scan --url https://mcp-server.example.com/mcp --severity high ``` ## Exit Codes - `0` — Scan completed, no critical findings - `1` — Error (invalid key, rate limit, scan failure) - `2` — Scan completed with critical findings ## Environment Variables - `MCPSHIELD_API_KEY` — API key (alternative to `mcpshield auth`) - `MCPSHIELD_API_URL` — Custom API endpoint (for self-hosted) ## License MIT