OpenTrustBench: A Fully Local, Zero-Telemetry MCP Server Security Scanner
BrilliantSecret143 · reddit · 2026-09-11
An Apache-2.0 open-source scanner for MCP servers with shell access: 8 OWASP-mapped static rules, permission manifests, and A-F Trust Cards. Runs fully offline with no API calls or telemetry, outputs SARIF for dashboards, ships a --fail-on gate for CI, and a one-line Docker image. The author invites the community to audit the rule set.
More from coding & agent
- Working with an ESP32 device using Copilot CLI and Astra — DanWahlin · 2026-09-11
- Hands-on: one reference image to a full dungeon with Aholo Lux3D + GPT-6 Astra + Blender — FinanceYF5 · 2026-09-11
- Dev Builds Local AI Memory System That Refuses to Hallucinate, Runs on One CPU Core — Unikum_01 · 2026-09-11
- The 2026 get-rich checklist: model tiering, agent fleets, and audience building — FinanceYF5 · 2026-09-11
- "I pay $600/month and hit Codex limits on 3 of 4 accounts": Astra 6 caps spark backlash — AIandDesign · 2026-09-11
- Faustus Open-Sourced: PewDiePie's Odysseus Fork Evolves Into a Full Local AI Workstation — Capital-Rich-9529 · 2026-09-11