Browser MCP scanner flags shell exec, secrets, and unsafe deserialization
KookyTax5493 · reddit · 2026-08-04
A browser-based demo turns the MCP scanner into a no-install static analysis tool for MCP servers, flagging risky patterns before they ship.
- Paste an MCP server file and it reports findings such as shell exec, hardcoded secrets, unsafe deserialization, and arbitrary file writes.
- The demo runs fully client-side, so nothing is sent to a server.
- The author says work is still in progress on live probing over HTTP/SSE and additional host adapters.
More from coding & agent
- Long-context voice agents ditch turn detection with async compaction handoff — juberti · 2026-08-04
- Phone-installable PWAs become custom AI agents with Tailscale and Codex — johnlindquist · 2026-08-04
- DeepSeek V4 Flash tops its price tier on GBench and looks much smarter in one-shot tasks — teortaxesTex · 2026-08-04
- Agent DevTools debugs memory, retrieval, and tool calls in local runs — No_Firefighter8428 · 2026-08-04
- Codex edited a full three-camera episode end to end in under 3 hours — danshipper · 2026-08-04
- CTO says an engineer automated 60% of his job with an AI agent and got promoted — sloppenheimer · 2026-08-04