Open Source MCP Security Scanner and Leaderboard
tatar-sh · reddit · 2026-07-19
MCPRadar is an MIT-licensed open-source MCP security scanner and public leaderboard.
It combines MCP attack surface, source code, configuration, dependencies, and snapshot analysis to output results in console, JSON, and SARIF formats. It emphasizes: treating MCP packages and responses as untrusted input, distinguishing full/partial/failed scans, avoiding false positives where incomplete results are marked as "clean", isolating stdio servers in disposable containers, and ensuring reproducible scoring and findings.
The author is looking for more real-world MCP servers for testing, allowing maintainers and users to submit manual scan requests. They also welcome community feedback on the scoring model, false positive handling, and currently underrepresented MCP-specific risks.
Related event: MCPRadar Launches as Open-Source MCP Security Scanner(2 posts)→
More from coding & agent
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- Running the Firefox MCP on Android via Termux, ngrok, and mcp-proxy — Nervous-Strain7544 · 2026-09-11
- SmolVM open-sources persistent computer infrastructure for agents that outlive chat sessions — aniketmaurya · 2026-09-11
- ARRM targets silent economic regressions in AI agents that functional tests miss — Beautiful_Belt_601 · 2026-09-11