Compuute MCP Security Scanner
Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back.
Open source Open in the app JSON
About
Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back.
37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning).
This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly.
POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review.
Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.
Details
- Kind
- MCP servers
- Topic
- Security & identity
- Publisher
- daniel-abbay
- Origin
- smithery
- Category
- ferramentas
- Transport
- desconhecido
- Added
- 2026-08-30 01:40:17
- Updated
- 2026-08-30 01:40:17
- Origin id
daniel-abbay/compuute-scan-api