mcpscan-cli
PulseGate's liveness check found it on 3 Oct 2026; it is registered on PyPI and has been in the index since 10 Aug 2026. How this is checked
mcpscan-cli is an open-source command-line security scanner for MCP servers and Claude Code projects. It detects tool poisoning, command injection, prompt-injection risks, and unsafe permissions before installation.
Inferred · not functionally tested
Overview
6 featuresPurpose: Preventing unsafe MCP servers and Claude Code projects from introducing supply-chain, injection, or permission risks.
Inferred · not functionally tested
Audience: developers and security engineers
Inferred · not functionally tested
Functions: Unknown
Interfaces: API: unknown · MCP: indicated (inferred, not tested) · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)
Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org. These links do not verify the individual claims.
In the Penetration testing & red teaming space, mcpscan-cli takes a focused approach. Inferred · not functionally tested: It focuses on preventing unsafe MCP servers and Claude Code projects from introducing supply-chain, injection, or permission risks. Inferred · not functionally tested: mcpscan-cli is an open-source project aimed at developers and security engineers. Basis unknown · not verified: mcpscan-cli is open source under the MIT license. Basis unknown · not verified: It runs on the command line, and it can be self-hosted.
mcpscan-cli first shipped in 2026. Inferred · not functionally tested: Key capabilities include MCP scanning, supply-chain scanning, and tool-poisoning detection. Basis unknown · not verified: Catalogued interfaces include an MCP server.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- MCP scanning
- Supply-chain scanning
- Tool-poisoning detection
- Command injection detection
- Permission analysis
- Claude Code scanning
Topics: Inferred · not functionally tested
Built with & integrations
Trust & compliance
Indexing history
1What PulseGate has recorded for this listing
- Indexed10 Aug · 17:01 UTCmcpscan-cli seen via PyPI Bulk EnumeratorSource: PyPI Bulk Enumerator · Open
Frequently asked questions about mcpscan-cli
- What is mcpscan-cli?
- Inferred · not functionally tested: Mcpscan-cli focuses on preventing unsafe MCP servers and Claude Code projects from introducing supply-chain, injection, or permission risks. It is catalogued under Penetration testing & red teaming on PulseGate.
- Who should use mcpscan-cli?
- Inferred · not functionally tested: mcpscan-cli is an open-source project built for developers and security engineers.
- Is mcpscan-cli free?
- Basis unknown · not verified: Yes — mcpscan-cli is open source under the MIT license and free to use.
- What platforms does mcpscan-cli run on?
- Basis unknown · not verified: mcpscan-cli runs on the command line. It can also be self-hosted.
- Is mcpscan-cli still active?
- PulseGate's liveness check found it on 3 Oct 2026.
- What are alternatives to mcpscan-cli?
- Similar projects tracked by PulseGate include mcp-security-scan, mcpsecscan, and mcpsnare.mcp-security-scanmcpsecscanmcpsnare
- How long has mcpscan-cli been around?
- mcpscan-cli first shipped in 2026.
- Is mcpscan-cli open source?
- Basis unknown · not verified: Yes — mcpscan-cli is open source under the MIT license.
Similar projects
Closest matches by what these projects do