Call for MCP Server Security Scans

tatar-sh · reddit · 2026-07-19

The author is continuing to accept MCP server submissions for scanning, noting that **MCPRadar** checks for multiple risk categories: tool poisoning and prompt injection, dangerous or misleading schemas, secret leakage and insecure configurations, vulnerable dependencies and supply chain risks, anomalous changes between server versions, and cross-server attack paths. The public leaderboard displays scan coverage, findings, risk levels, and downloadable artifacts. New server additions require manual review, meaning **submission requests do not automatically execute commands**, and publication is not guaranteed. The author also invites community feedback on: which servers to include, any false positives or disputed ratings, missing MCP attack vectors, and how to make the scoring methodology clearer.

Related event: MCPRadar Launches as Open-Source MCP Security Scanner(2 posts)→

Original post →

More from coding & agent

coding & agent channel →