Prism Scanner runs on your own machine — the client starts it, so there is no endpoint to ping. 108 installs a week from pypi. Last commit 7 Apr 2026.
Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
We read the source, 20 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
result = subprocess.run(
pattern: "(?:\\.ssh|id_rsa|id_ed25519)[^\\n]{0,120}(?:requests\\.post|urllib\\.request|httpx\\.post)|(?:requests\\.post|urllib\\.request|httpx\\.post)[^\\n]{0,120}(?:\\.ssh|id_rsa|id_ed25519)"
- "*.ngrok.io"
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add prism-scanner -- uvx prism-scanner
{
"mcpServers": {
"prism-scanner": {
"args": [
"prism-scanner"
],
"command": "uvx"
}
}
}
[mcp_servers.prism-scanner]
command = "uvx"
args = ["prism-scanner"]
{
"mcpServers": {
"prism-scanner": {
"args": [
"prism-scanner"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"prism-scanner": {
"args": [
"prism-scanner"
],
"command": "uvx"
}
}
}
Security scanner for AI agent skills and MCP servers
Security scanner and runtime proxy for MCP servers.
Multi-layer security scanner for MCP servers and agent skills (injection, exfiltration)
Search and install 20,000+ security-graded MCP servers and agent skills.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Security scanner for MCP servers - detects tool poisoning and injection
Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
Pre-install security scanner for AI agent skills (local stdio MCP). Offline static scan; no upload.
Answers built from our own checks of this server.