Back to Home
kapilduraphe icon

mcp-watch

Verified Safe

by kapilduraphe

Overview

A comprehensive security scanner for Model Context Protocol (MCP) servers that detects various vulnerabilities in MCP implementations.

Installation

Run Command
npx mcp-watch scan https://github.com/user/mcp-server

Environment Variables

  • NODE_ENV

Security Notes

The scanner uses 'spawnSync' to execute 'git clone' for remote repository analysis. While arguments are passed safely as an array to prevent shell injection, executing arbitrary git commands on potentially untrusted repositories, even in temporary directories, inherently carries a small risk. The tool actively sanitizes detected credentials in its output to prevent self-leakage, which is a strong security practice for a security scanner.

Similar Servers

Stats

Interest Score57
Security Score8
Cost ClassLow
Stars111
Forks12
Last Update2025-12-07

Tags

SecurityVulnerability ScannerMCPCode AnalysisAI Security