MCP Security & Vulnerability Auditor is answering right now. Last checked 2 min ago. It exposes 1 tools. Last commit 12 Sep 2026.
Static AST security scanner detecting command injection, leaked secrets, and SSRF in MCP tools.
We read the source, 22 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
subprocess.run(
is_shell = True
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 2 min ago.
claude mcp add mcp-security-auditor --transport http https://neoninnovationlab.com/api/mcp-security
{
"mcpServers": {
"mcp-security-auditor": {
"url": "https://neoninnovationlab.com/api/mcp-security"
}
}
}
[mcp_servers.mcp-security-auditor]
url = "https://neoninnovationlab.com/api/mcp-security"
{
"mcpServers": {
"mcp-security-auditor": {
"url": "https://neoninnovationlab.com/api/mcp-security"
}
}
}
{
"mcpServers": {
"mcp-security-auditor": {
"url": "https://neoninnovationlab.com/api/mcp-security"
}
}
}
This server publishes 1 more address. The block above uses the one we reach during checks; the full list is under Endpoints below, and the author may intend a particular one for your client.
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
audit_mcp_security
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://neon_innovation_lab--mcp-security-auditor.apify.actor/mcp | streamable-http | answering | 387 ms | 2 min ago |
| https://neoninnovationlab.com/api/mcp-security | sse | answering | 606 ms | 2 min ago |
AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
MCP server security scanner: detects prompt injection, credential leaks, SSRF, tool poisoning.
Security scanner for MCP servers - detects tool poisoning and injection
Scan AI agents for tool-calling vulnerabilities: prompt leaks, hijacking, injections, and more.
Security gateway for AI agents: detects prompt injections, jailbreaks, and common vulnerabilities.
Scan installed MCP servers for security vulnerabilities with 16 detection engines.
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Answers built from our own checks of this server.