‹ The Index

Scan

npm

Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Security — see all ranked ›

Install (Claude Code):

claude mcp add can -- npx -y owasp-mcp-scan

Security audit

scanned 2026-07-30

Every finding is shown in full. Nothing on this page is behind a licence — there is no advisory to name and no install script to read.

No known advisoriesclearchecked against OSV for 0.2.1
No permission surface detecteddeclares no dependency that reaches files, shell or network
No build provenanceno attestation — the published artifact cannot be traced to its source

npm ↗  ·  source ↗  ·  pkg:owasp-mcp-scan

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›