MCPAmpel - MCP Security Scanner runs on your own machine — the client starts it, so there is no endpoint to ping. 69 installs a week from pypi. Last commit 2 Apr 2026.
Scan installed MCP servers for security vulnerabilities with 16 detection engines.
Today is the operative word: we check MCPAmpel - MCP Security Scanner every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcpampel -- uvx mcpampel
{
"mcpServers": {
"mcpampel": {
"args": [
"mcpampel"
],
"command": "uvx"
}
}
}
[mcp_servers.mcpampel]
command = "uvx"
args = ["mcpampel"]
{
"mcpServers": {
"mcpampel": {
"args": [
"mcpampel"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"mcpampel": {
"args": [
"mcpampel"
],
"command": "uvx"
}
}
}
This one needs environment variables set before it will start:
MCPAMPEL_API_KEY (MCPAmpel API key (get one free at mcpampel.com)).
The author declared them in the registry entry; get the values from the project itself.
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
AI-Powered Security Scanner for LLMs. Detects vulnerabilities and syncs with SynapseAudit.
Security scanner for MCP servers - detects tool poisoning and injection
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
AI-powered security scanning using Black Duck Signal for vulnerability detection.
Security co-pilot for AI agents. Scan for vulnerabilities, audit MCP servers, verify governance.
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Answers built from our own checks of this server.