Sponsor MCPSafe10 founding slots
Trusted by developers worldwide

Secure Your MCP Servers

MCPSafe is the security scanner and quality registry for Model Context Protocol servers. Registry metadata is live; public security findings are published only after review gates pass.

Popular:

Trusted by the MCP Community

Live registry metadata and reviewed security intelligence for Model Context Protocol servers

0+
Verified Servers
0+
Security Scans
0+
Risk Signals Processed
0+
Security Rules
Verified Registry

Featured MCP Servers

Verified MCP server entries with live source metadata. Security scores return only after reviewed findings are enabled.

MCP Risk Signals

Findings MCPSafe Highlights

Public vulnerability claims stay behind review gates, but the homepage should still show the MCP-specific risk classes our scanner looks for.

Why MCPSafe?

Security analysis for MCP servers with reviewed-publication gates to avoid unverified claims.

Security Scanning

Deep analysis of MCP server code for vulnerabilities, unsafe patterns, and potential security risks.

Code Analysis

AST-based parsing to detect command injection, credential exposure, and dangerous API usage.

Trust Registry

Browse verified MCP servers with source, popularity, quality, freshness, and reviewed security data kept separate and readable.

Built for AI Agents

Connect Your Agent in Seconds

One endpoint. Full security intelligence. Built for Claude, GPT, and any AI agent.

Quick Start — Get Service Info

No auth required. Your agent can discover all capabilities instantly.

GEThttps://api.mcpsafe.org/api/agent/info

Response:

{
  "service": "MCPSafe",
  "capabilities": ["scan_url", "get_report", "get_badge"],
  "endpoints": {
    "scan": "POST /api/v1/scans/url",
    "badge": "GET /api/badge/{slug}.svg"
  },
  "free_tier": { "scans_per_month": "unlimited" }
}

Instant Scans

Submit any GitHub URL, get security results in seconds

Security Badges

Embed trust badges for any scanned server

Full Registry

Query verified MCP servers with security and quality scores

Free public registry access and server scanning while the reviewed-security publication layer is finalized.

Powerful Features

Everything You Need for MCP Security

From source-aware code analysis to readable registry cards, MCPSafe separates security, quality, usage, and freshness so users can understand why a server ranks where it does.

AST-Based Analysis

Tree-sitter powered parsing for JavaScript, TypeScript, and Python. Analyze code structure without executing it.

50+ Security Rules

Comprehensive rule set covering OWASP Top 10, command injection, path traversal, SSRF, and more.

Real-Time Scanning

Scan any MCP server in seconds. Submit a GitHub URL, npm package, or upload source code directly.

Vulnerability Details

Get detailed reports with code snippets, line numbers, CWE IDs, CVSS scores, and remediation guidance.

CI/CD Integration

GitHub Actions and CLI tools to automate security checks in your development workflow.

Security Alerts

Get notified when new vulnerabilities are discovered in servers you're watching.

API Access

Full REST API with OpenAPI documentation. Build custom integrations and workflows.

Multi-Factor Scoring

Separate security, MCP risk, supply-chain, quality, popularity, and freshness signals roll into a clear trust view without hiding the underlying data.

Registry Discovery

Browse the verified MCP registry, backed by live source checks and strict cleanup of non-server packages.

100% Free

100% Free — No Limits

Every feature is free for everyone. Unlimited scans, full registry access, API access, webhooks, and more — no credit card required.

  • Full registry access — all servers
  • Unlimited security scans
  • Detailed vulnerability reports
  • Full API access
  • Unlimited watchlist
  • Webhook notifications
  • CI/CD integration
  • Email alerts

Ready to secure your MCP servers?

Everything is free — create an account and start scanning in seconds.