Call for MCP Server Security Scans

tatar-sh · reddit · 2026-07-19

The author is continuing to accept MCP server submissions for scanning, noting that MCPRadar checks for multiple risk categories: tool poisoning and prompt injection, dangerous or misleading schemas, secret leakage and insecure configurations, vulnerable dependencies and supply chain risks, anomalous changes between server versions, and cross-server attack paths.

The public leaderboard displays scan coverage, findings, risk levels, and downloadable artifacts. New server additions require manual review, meaning submission requests do not automatically execute commands, and publication is not guaranteed.

The author also invites community feedback on: which servers to include, any false positives or disputed ratings, missing MCP attack vectors, and how to make the scoring methodology clearer.

Related event: MCPRadar Launches as Open-Source MCP Security Scanner(2 posts)→

Original post →

More from coding & agent

coding & agent channel →