348 packages scanned
4,251 vulnerabilities found
269 scans this week

Grade backed by static analysis + 5 LLMs.

Is this MCP server safe to install? Get an AIVSS score in under a minute — no signup required for public repos.

What we detect

!

Typosquatting

Flags lookalike package names, unverified publishers, and unpinned dependencies before they reach your install chain.

Static analysis

Detects command injection, SQL injection, SSRF, path traversal, and hardcoded secrets — the code-level bugs that turn MCP servers into exploits.

LLM consensus

Five independent LLM judges uncover tool poisoning, silent rug pulls, indirect prompt injection, and obfuscated intent that pattern matching misses.

Permission audit

Audits each tool's real-world reach — flagging excessive permissions, weak authentication, and network exposure beyond its stated purpose.

How it works

01

Paste any MCP source

GitHub URL, npm scoped package, or pip package — we normalise them all. Pin a specific version with @version.

02

Parallel analysis

Typosquat, static, behavioral, readiness, and 5-LLM consensus run in parallel across commit fingerprints.

03

Actionable score report

AIVSS 0–10 score, per-tool findings, CWE mapping, and copy-safe config snippets. Previously scanned packages return in under a second.

The AIVSS scoring system

AI Vulnerability Severity Score extends CVSS with agentic-threat factors.

A
Score 90–100. Verified safe. Low risk.
B
Score 70–89. Minor findings. Review recommended.
C
Score 50–69. Medium risk. Review before install.
D
Score 20–49. High risk. Use with caution.
F
Score 0–19. Critical findings. Do not install.
Free · No credit card required

Ship safer MCP integrations.

The MCP ecosystem moves fast. Security tooling for it doesn't — yet. MCPSafe brings automated scanning, multi-LLM consensus, and AIVSS scoring to every package before it touches your agent.