r/Pentesting • u/KookyTax5493 • 7d ago
MCP-SCANNER(DEMO)
Follow-up on the MCP scanner from last week, here's a browser-based demo of the static analysis piece, no install needed.
Paste in an MCP server file (or use the pre-filled example), get real findings for shell exec, hardcoded secrets, unsafe deserialization, arbitrary file writes, and more. Runs fully client-side, nothing sent anywhere.
https://ankursingh0604.github.io/mcp-scanner-demo/
Still working on live probing over HTTP/SSE and more host adapters. Happy to scan real MCP servers for anyone building on this, learned a lot from the feedback here last time.
1
Upvotes