Capability audit tool #1808
vinmay
started this conversation in
Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I built a static analysis CLI that audits MCP server code for real-world capabilities (shell execution, credential access, file I/O, dynamic code execution) and which of those capabilities are reachable through registered tools - reachscan.
I recently completed a scan of 50 MCP server repos and published the results:
The full write up is here: I Scanned 50 MCP Servers to See What They Can Actually Do
I'm reaching out because I think this information is relevant to the MCP/Agent related work on security guidance for authors.
I'm looking to understand whether the tool and data are useful to this work, and if so, how can I contribute more towards it.
Beta Was this translation helpful? Give feedback.
All reactions