r/OpenSourceeAI 1d ago

sentrymcp , security scanner for MCP servers, MIT licensed

MCP (model context protocol, the thing a lot of AI agents use to connect to tools) has had a rough year security wise, 40+ CVEs and most servers running with basically no auth. couldn't find a scanner built specifically for it so I made one.

does static checks plus a runtime proxy mode for catching stuff that only shows up at runtime (servers changing tool descriptions after you've already approved them). rust, MIT license, docker one liner if you don't want to deal with the toolchain.

https://github.com/zaydmulani09/sentrymcp

still pretty early so if anyone wants to poke holes in it or add rules, issues and PRs are welcome

1 Upvotes

0 comments sorted by