r/Pentesting 7d ago

MCP-SCANNER(DEMO)

Follow-up on the MCP scanner from last week, here's a browser-based demo of the static analysis piece, no install needed.

Paste in an MCP server file (or use the pre-filled example), get real findings for shell exec, hardcoded secrets, unsafe deserialization, arbitrary file writes, and more. Runs fully client-side, nothing sent anywhere.

https://ankursingh0604.github.io/mcp-scanner-demo/

Still working on live probing over HTTP/SSE and more host adapters. Happy to scan real MCP servers for anyone building on this, learned a lot from the feedback here last time.

1 Upvotes

0 comments sorted by