Get a security assessment of MCP servers directly from your terminal
Get a security assessment of MCP servers directly from your terminal
I built a deterministic scanner that catches command injection, prompt-injection markers in tool descriptions, over-broad/destructive tools, and committed secrets in MCP servers before you connect them. It continuously scans the entire official MCP registry and makes results available at https://index.canopii.dev . Now the engine behind that scanner is available as a CLI that you can integrate into your processes and CI/CD pipelines (e.g --min-grade B). If you are building MCP servers, you can make sure your MCP server is secure using the local mode before publishing it. Or check why your server scored low, apply fixes, check if your score has improved locally first before publishing a new version so as to eliminate guesswork. If you are a user, easily check the security of an MCP server before connecting your AI agents using one of the available methods (remote, github, pypi, npm etc.) You can also use an LLM as a "judge". It won't affect the score but it may flag important security considerations that a deterministic scanner can't catch. No telemetry, no account necessary. Github: https://github.com/canopii-dev/canopii-cli (license: Apache 2.0)
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Representing Agents as MCP Servers
Chat with 1000s of MCP servers
GuardiAgent – Sandboxing / permission model for MCP servers
MCP Servers, in one place
Mcploitable – Vulnerable MCP Servers for the OWASP Agentic Top
Fast MCP – A Ruby gem to create MCP servers
ContextGuard – Open-source security monitoring for MCP servers
MCP Servers Directory
Directory of MCP servers
OAuth 2.0 framework for MCP servers