Skip to content
Back to the index

mcp-bandit

github.comInfrastructure

PulseGate's liveness check found it on 13 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 25 Jun 2026. How this is checked

mcp-bandit is an open-source command-line tool for scanning Model Context Protocol (MCP) servers for security vulnerabilities, including prompt injection and SSRF. It is designed for security engineers to audit and analyze MCP deployments.

Inferred · not functionally tested

Open SourceMITWebCLI
mcp-bandit preview
Visit github.com

Overview

5 features

Purpose: Detecting security vulnerabilities and prompt injection risks in MCP servers.

Inferred · not functionally tested

Audience: security engineers

Inferred · not functionally tested

Functions: monitoring

Inferred · not functionally tested

Interfaces: API: unknown · MCP: indicated (inferred, not tested) · CLI: indicated (inferred, not tested) · Self-hosting: unknown

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: browser, cli

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: github.com. These links do not verify the individual claims.

mcp-bandit sits in PulseGate's Penetration testing & red teaming category. Inferred · not functionally tested: It focuses on detecting security vulnerabilities and prompt injection risks in MCP servers. Inferred · not functionally tested: It is built as an open-source project for security engineers. Basis unknown · not verified: mcp-bandit is open source under the MIT license. Basis unknown · not verified: mcp-bandit is available on the web and the command line.

It is developed by Giridhar Pandurangi, and it first shipped in 2026. Development happens publicly on GitHub with 7 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include MCP scanning, prompt injection detection, and static analysis. Basis unknown · not verified: Catalogued interfaces include an MCP server.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • MCP scanning
  • Prompt injection detection
  • Static analysis
  • Security auditing
  • CLI tool

Topics: Inferred · not functionally tested

Tags
mcp-securityprompt-injectioncli-scanner

JSON profile · Text profile · Access guide

Built with & integrations

Connectors
MCP
Runs on
BrowserCLI

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceFree tierGitHubActive maintenance

Indexing history

What PulseGate has recorded for this listing

Nothing recorded for this listing in this window.

Frequently asked questions about mcp-bandit

What is mcp-bandit?
Inferred · not functionally tested: Mcp-bandit focuses on detecting security vulnerabilities and prompt injection risks in MCP servers. It is catalogued under Penetration testing & red teaming on PulseGate.
Who is mcp-bandit for?
Inferred · not functionally tested: mcp-bandit is an open-source project built for security engineers.
Is mcp-bandit free?
Basis unknown · not verified: Yes — mcp-bandit is open source under the MIT license and free to use.
What platforms does mcp-bandit run on?
Basis unknown · not verified: mcp-bandit runs on the web and the command line.
Is mcp-bandit still active?
PulseGate's liveness check found it on 13 Sep 2026. Its GitHub repository shows 7 commits in the last 90 days.
What projects are similar to mcp-bandit?
Similar projects tracked by PulseGate include mcpsec, mcp-audit-scanner, and mcp-recon.mcpsecmcp-audit-scannermcp-recon
Who makes mcp-bandit?
mcp-bandit is developed by Giridhar Pandurangi.
How long has mcp-bandit been around?
mcp-bandit first shipped in 2026.

Similar projects

Closest matches by what these projects do