Security scanner for MCP servers. SSRF, path traversal, injection, auth, secrets. Grade A-F.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Open-source security scanner for MCP servers. 20 rules across 6 categories. Scan any server in seconds. Get a grade from A to F.
36.7% of MCP servers are SSRF-vulnerable (BlueRock, 2026). 82% have path traversal flaws. Only 17% are production-ready. MCP Shield finds the vulnerabilities before attackers do.
| Rule | Severity | What It Detects |
|---|---|---|
| SSRF-01 | Critical | User input in HTTP request URLs |
| SSRF-02 | Medium | Dynamic URLs without validation |
| SSRF-03 | Medium | DNS rebinding (URL validated but no IP pinning) |
| PATH-01 | High | User input in file paths |
| PATH-02 | Medium | No path traversal protection |
| PATH-03 | Medium | Symlink following without check |
| INJ-01 | Critical | eval/exec on user input |
| INJ-02 | Critical | SQL string interpolation |
| INJ-03 | High | subprocess with shell=True |
| INJ-04 | High | Template injection via .format() |
| INJ-05 | Critical | Unsafe deserialization (pickle/yaml) |
| AUTH-01 | Medium | No auth on tool handlers |
| AUTH-02 | Critical | Hardcoded secrets/API keys (OpenAI, Stripe, GitHub, AWS) |
| AUTH-03 | Low | No rate limiting on tool endpoints |
| SEC-01 | High | SSL verification disabled |
| SEC-02 | Medium | Wildcard CORS |
| SEC-03 | Medium | Stack traces/error details exposed to client |
| SEC-04 | Low | No input length validation (DoS risk) |
| LOG-01 | Low | No logging/audit trail on tool invocations |
Add to ~/.claude/mcp.json:
Claude Code tools: shield_scan_file, shield_scan_directory, shield_scan_code
The MCP ecosystem has 9,400+ servers and 97M monthly SDK downloads. Security tooling hasn't kept up. We built MCP Shield because every MCP server deployed without a security scan is a liability.
Built by Like One, a 501(c)(3) nonprofit. Security tooling should be free.
MIT β Like One
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-shield-2)<a href="https://allmcps.com/mcp/mcp-shield-2"><img src="https://allmcps.com/api/badge/mcp-shield-2?style=directory" alt="MCP Shield on AllMCPs" /></a>