MCPSafe
Scans MCP servers to detect code and supply-chain vulnerabilities before installation
The product is a security scanner for MCP servers that identifies code and supply-chain risks such as injection flaws, typosquatting, tool poisoning, and excessive permissions before installation. It is for developers vetting third-party servers and registry operators publishing catalogs, as well as teams scanning private repositories, serving B2B users. It is delivered as a SaaS with a fast automated verdict and a deeper five-model consensus analysis, offering public package scans free and private scans for teams.
Key features
- Typosquatting detection
- Static analysis for injections
- LLM consensus for tool poisoning
- Permission audit per tool
- AIVSS 0-10 scoring
- CWE mapping
- Copy-safe config generation
- Live SVG grade badge
- Version fingerprinting and caching
- Scan GitHub URLs
- Scan npm packages
- Scan PyPI packages
- Scan Docker images
- Scan MCP registry IDs
- No social media activity within the last 30 days
GTM channels
- Marketplace
- API
- Docs
ICP
- Software developers
- Security teams
- IT teams