mcp-pin is an Apache-2.0 licensed, zero-dependency command-line security scanner for MCP servers and agent skills. It helps developers identify security and supply-chain risks and supports SARIF-oriented security workflows.
mcp-pin is an AI & LLM security project. It focuses on scanning MCP servers and agent skills for security and supply-chain risks. It is built as an open-source project for developers building or auditing AI agents. The project is open source (Apache-2.0). It ships for the command line, and it can be self-hosted.
Rufat325 builds and maintains mcp-pin, and it first shipped in 2026. Development happens publicly on GitHub with 119 commits in the last 90 days. Among its 5 catalogued features are MCP scanning, agent skill scanning, and supply-chain checks. It exposes integrations via an MCP server.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do