Ross ROSS = Recommend OSS · open-source software intelligence for agents

cisco-ai-defense/mcp-scanner

Scan MCP servers for potential threats & security findings. observed · 2026-08-28

github.com/cisco-ai-defense/mcp-scanner · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

83/100

  • Activity 99
  • Release rhythm 96
  • Longevity 24
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 2.0
  • age_days: 344
  • days_rel: 26
  • days_push: 8
  • n_releases_24m: 45

Full methodology

Adoption not part of the score

1051 stars · 132 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

MCP Scanner is a Python tool and SDK from Cisco AI Defense that scans Model Context Protocol (MCP) servers, tools, prompts, and resources for security threats. It combines YARA rules, LLM-based analysis, and the Cisco AI Defense inspect API, and can run as a CLI or REST API server.

Use cases

  • scan mcp servers for malicious tools before connecting agents
  • audit ai agent supply chain for security threats
  • detect tool poisoning in model context protocol servers
  • scan pypi packages used by mcp servers for malware
  • run mcp security scans in ci/cd pipelines
  • check mcp server code for behavioral threats

When to choose

  • you deploy or consume MCP servers and need to vet them for security findings
  • you want multi-engine scanning (YARA, LLM, Cisco AI Defense) of MCP tools, prompts, and resources
  • you need offline/static scanning of MCP server metadata for air-gapped or CI environments

When to avoid

  • you need general-purpose vulnerability scanning of non-MCP software
  • you require a fully self-contained scanner with no reliance on external APIs like Cisco AI Defense or VirusTotal
  • you need runtime protection of agents rather than pre-deployment scanning

Facets

cli-tool · maturity active

security vulnerability-scanning mcp cli developer-tools security developer-tools large-language-models python cli cross-platform mcp-security supply-chain-security yara-rules llm-analysis ai-agent-supply-chain pypi-package-scanning virus-total ai-agents docker

2 sources

Member repositories

RepositoryRoleHealth v2
cisco-ai-defense/mcp-scannermain83

For agents

markdown · JSON · MCP: product_card(name="cisco-ai-defense/mcp-scanner")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem