Open Source MCP Security Scanner and Leaderboard
tatar-sh · reddit · 2026-07-19
MCPRadar is an MIT-licensed open-source MCP security scanner and public leaderboard.
It combines MCP attack surface, source code, configuration, dependencies, and snapshot analysis to output results in console, JSON, and SARIF formats. It emphasizes: treating MCP packages and responses as untrusted input, distinguishing full/partial/failed scans, avoiding false positives where incomplete results are marked as "clean", isolating stdio servers in disposable containers, and ensuring reproducible scoring and findings.
The author is looking for more real-world MCP servers for testing, allowing maintainers and users to submit manual scan requests. They also welcome community feedback on the scoring model, false positive handling, and currently underrepresented MCP-specific risks.
Related event: MCPRadar Launches as Open-Source MCP Security Scanner(2 posts)→
More from coding & agent
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11
- RTK Terminal Compression Cuts Tokens but Leaves Your AI Coding Bill Unchanged — Bartaseth · 2026-09-11
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11