Skip to content
Back to the index

mcpscan-cli

PyPIInfrastructure

PulseGate's liveness check found it on 3 Oct 2026; it is registered on PyPI and has been in the index since 10 Aug 2026. How this is checked

mcpscan-cli is an open-source command-line security scanner for MCP servers and Claude Code projects. It detects tool poisoning, command injection, prompt-injection risks, and unsafe permissions before installation.

Inferred · not functionally tested

Open SourceMITCLISelf-hosted
Visit PyPI

Overview

6 features

Purpose: Preventing unsafe MCP servers and Claude Code projects from introducing supply-chain, injection, or permission risks.

Inferred · not functionally tested

Audience: developers and security engineers

Inferred · not functionally tested

Functions: Unknown

Interfaces: API: unknown · MCP: indicated (inferred, not tested) · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org. These links do not verify the individual claims.

In the Penetration testing & red teaming space, mcpscan-cli takes a focused approach. Inferred · not functionally tested: It focuses on preventing unsafe MCP servers and Claude Code projects from introducing supply-chain, injection, or permission risks. Inferred · not functionally tested: mcpscan-cli is an open-source project aimed at developers and security engineers. Basis unknown · not verified: mcpscan-cli is open source under the MIT license. Basis unknown · not verified: It runs on the command line, and it can be self-hosted.

mcpscan-cli first shipped in 2026. Inferred · not functionally tested: Key capabilities include MCP scanning, supply-chain scanning, and tool-poisoning detection. Basis unknown · not verified: Catalogued interfaces include an MCP server.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • MCP scanning
  • Supply-chain scanning
  • Tool-poisoning detection
  • Command injection detection
  • Permission analysis
  • Claude Code scanning

Topics: Inferred · not functionally tested

Tags
mcp-securitysupply-chain-scanningprompt-injectionclaude-codesecurity-scanner

JSON profile · Text profile · Access guide

Built with & integrations

Connectors
MCP
Runs on
CLISelf-hosted

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceFree tier

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed10 Aug · 17:01 UTC
    mcpscan-cli seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about mcpscan-cli

What is mcpscan-cli?
Inferred · not functionally tested: Mcpscan-cli focuses on preventing unsafe MCP servers and Claude Code projects from introducing supply-chain, injection, or permission risks. It is catalogued under Penetration testing & red teaming on PulseGate.
Who should use mcpscan-cli?
Inferred · not functionally tested: mcpscan-cli is an open-source project built for developers and security engineers.
Is mcpscan-cli free?
Basis unknown · not verified: Yes — mcpscan-cli is open source under the MIT license and free to use.
What platforms does mcpscan-cli run on?
Basis unknown · not verified: mcpscan-cli runs on the command line. It can also be self-hosted.
Is mcpscan-cli still active?
PulseGate's liveness check found it on 3 Oct 2026.
What are alternatives to mcpscan-cli?
Similar projects tracked by PulseGate include mcp-security-scan, mcpsecscan, and mcpsnare.mcp-security-scanmcpsecscanmcpsnare
How long has mcpscan-cli been around?
mcpscan-cli first shipped in 2026.
Is mcpscan-cli open source?
Basis unknown · not verified: Yes — mcpscan-cli is open source under the MIT license.

Similar projects

Closest matches by what these projects do