Open Source MCP Security Scanner and Leaderboard
tatar-sh · reddit · 2026-07-19
MCPRadar is an MIT-licensed open-source MCP security scanner and public leaderboard.
It combines MCP attack surface, source code, configuration, dependencies, and snapshot analysis to output results in console, JSON, and SARIF formats. It emphasizes: treating MCP packages and responses as untrusted input, distinguishing full/partial/failed scans, avoiding false positives where incomplete results are marked as "clean", isolating stdio servers in disposable containers, and ensuring reproducible scoring and findings.
The author is looking for more real-world MCP servers for testing, allowing maintainers and users to submit manual scan requests. They also welcome community feedback on the scoring model, false positive handling, and currently underrepresented MCP-specific risks.
Related event: MCPRadar Launches as Open-Source MCP Security Scanner(2 posts)→
More from coding & agent
- A Forward Deployed Engineer job really has three stages: audit, evals, deploy — blaizedsouza · 2026-07-22
- 438 sealed tests show coding agents prefer DIY over third-party databases — cramforce · 2026-07-22
- Tenable and AWS launch a Black Hat build event for open-source security agents and MCP servers — Dave_Maynor · 2026-07-22
- Codex helps build Valdiluce, an open-world game with climbing, gliding and gondolas — Dimillian · 2026-07-22
- HeyGen adds a media-sourcing skill for coding agents with 75k images and 10k tracks — HeyGen · 2026-07-22
- Agent search bottlenecks are now about variance, not raw latency — rohanpaul_ai · 2026-07-22