ShieldMCP is a web-based security scanner designed to assess MCP configuration files for vulnerabilities and risks. It addresses the need for proactive identification of security issues in MCP setups by scanning uploaded or pasted configuration files and flagging problems such as permission risks, exposed secrets, and supply chain threats. The tool performs a rapid scan, delivering results in approximately 60 seconds, and does not require users to create an account for the basic scan.
The scanner checks configurations against all categories in the OWASP MCP Top 10, including token mismanagement, privilege escalation, tool poisoning, software supply chain attacks, command injection, intent flow subversion, insufficient authentication, lack of audit, shadow MCP servers, and context injection. Users can upload files such as claude_desktop_config.json or .cursor/mcp.json, or paste JSON directly into the platform. After the scan, ShieldMCP provides risk scores, category flags, issue titles, and server ratings for free. For each identified issue, the platform offers explanations and, with a paid report, provides detailed fix steps and copy-paste JSON configuration examples.
ShieldMCP operates on a simple pricing model. The free tier includes essential findings and risk indicators, while a one-time payment of $49 per scan unlocks a full report featuring detailed remediation steps, configuration examples, prioritized issue ordering, and a shareable PDF. A Pro plan is listed as coming soon, which will offer features for teams such as API access for CI/CD, auto-rescan alerts, scan history, team configuration management, and Slack alerts for $19 per month.
This tool is intended for users responsible for managing or securing MCP deployments who want to quickly identify and address security vulnerabilities before they can be exploited. ShieldMCP focuses on comprehensive coverage of the OWASP MCP Top 10 vulnerabilities, providing a specialized solution for MCP security scanning and remediation.
ShieldMCP is an AI & LLM security project. It focuses on identifying and fixing security vulnerabilities in MCP server configurations quickly and easily. It is built as a B2B product for MCP administrators and security professionals. A free plan is available; paid tiers begin at $29. It ships for the web.
ShieldMCP first shipped in 2026. Among its 8 catalogued features are OWASP MCP Top 10 scan, config upload, and instant vulnerability scan. It exposes integrations via an MCP server.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do