OpenTrustBench: A Fully Local, Zero-Telemetry MCP Server Security Scanner

BrilliantSecret143 · reddit · 2026-09-11

An Apache-2.0 open-source scanner for MCP servers with shell access: 8 OWASP-mapped static rules, permission manifests, and A-F Trust Cards. Runs fully offline with no API calls or telemetry, outputs SARIF for dashboards, ships a --fail-on gate for CI, and a one-line Docker image. The author invites the community to audit the rule set.

Original post →

More from coding & agent

coding & agent channel →