Back to the catalog

Compuute MCP Security Scanner

Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back.

Open source Open in the app JSON

About

Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back.

37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning).

This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly.

POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review.

Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.

Details

Kind
MCP servers
Topic
Security & identity
Publisher
daniel-abbay
Origin
smithery
Category
ferramentas
Transport
desconhecido
Added
2026-08-30 01:40:17
Updated
2026-08-30 01:40:17
Origin id
daniel-abbay/compuute-scan-api

More