Mception runs on your own machine — the client starts it, so there is no endpoint to ping. 41 installs a week from pypi.
Audits other MCP servers for security risks. Returns safe / caution / unsafe / inconclusive.
Today is the operative word: we check Mception every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mception -- uvx mception
{
"mcpServers": {
"mception": {
"args": [
"mception"
],
"command": "uvx"
}
}
}
[mcp_servers.mception]
command = "uvx"
args = ["mception"]
{
"mcpServers": {
"mception": {
"args": [
"mception"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"mception": {
"args": [
"mception"
],
"command": "uvx"
}
}
}
This one needs environment variables set before it will start:
MCEPTION_DATA_DIR (Where audit reports and rug-pull baselines live. Defaults to ~/.mception.), MCEPTION_OFFLINE (Set to 1 to block outbound HTTP (OSV, registry signals, phantom-repo probes).), MCEPTION_INTROSPECT_TIMEOUT (Per-target timeout in seconds for the fetcher + engine pipeline.), MCEPTION_ENABLE_LLM_JUDGE (Set to 1 to enable advisory LLM-assisted classification via MCP sampling. No API key needed.).
The author declared them in the registry entry; get the values from the project itself.
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
MCP server for Security
Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.
Security scanner for MCP servers - detects tool poisoning and injection
Security scanner for MCP servers. SSRF, path traversal, injection, auth, secrets. Grade A-F.
MCP server for JavaScript analysis, security auditing, browser automation and hooks
Answers built from our own checks of this server.