Open Source MCP Security Scanner and Leaderboard

tatar-sh · reddit · 2026-07-19

MCPRadar is an MIT-licensed open-source MCP security scanner and public leaderboard.

It combines MCP attack surface, source code, configuration, dependencies, and snapshot analysis to output results in console, JSON, and SARIF formats. It emphasizes: treating MCP packages and responses as untrusted input, distinguishing full/partial/failed scans, avoiding false positives where incomplete results are marked as "clean", isolating stdio servers in disposable containers, and ensuring reproducible scoring and findings.

The author is looking for more real-world MCP servers for testing, allowing maintainers and users to submit manual scan requests. They also welcome community feedback on the scoring model, false positive handling, and currently underrepresented MCP-specific risks.

Related event: MCPRadar Launches as Open-Source MCP Security Scanner(2 posts)→

Original post →

More from coding & agent

coding & agent channel →