Free Online Tool

MCP Server Security Scanner

Point it at any domain to find its MCP server, check whether it's locked down, and see what a connected AI can actually do through it. Mapped to the OWASP MCP Top 10.

Try:
No account requiredNon-destructiveResults in seconds

What our MCP scanner analyzes

An MCP server is not just another web page, it is a doorway that lets an AI agent take real actions and read real data on your behalf. Our scanner looks at that doorway the way an outside attacker would, and tells you whether it is safe to leave open.

Agent surface discovery

Finds the MCP servers and agent endpoints exposed on your domain, the part of your site an AI agent can reach that most teams have never looked at.

Authentication

Confirms your server actually requires a credential, and is not quietly answering tool calls from anyone on the internet.

Authorization & login

Checks that the OAuth and token setup protecting agent access follows current best practice, not a shape attackers have learned to abuse.

Tools, resources & prompts

Shows exactly what a connected AI can do and read through your server, and flags anything that is over-exposed or state-changing.

Prompt-injection surface

Detects hidden or manipulative instructions in what your server tells a connected model, the way attackers turn an agent against its own user.

Known vulnerabilities (CVEs)

When a server reveals its software and version, we match it against the OSV vulnerability database and flag any known CVEs, with the severity and the exact version to upgrade to.

Deep exposure checks

Bounded active checks for the misconfigurations that turn an agent endpoint into an incident. Available on Pro.

What your MCP report looks like

Every scan returns a clear grade, a category breakdown, and a prioritized list of findings, each written in plain English with why it matters. It reads exactly like our main security report, so it drops straight into an audit or a client review.

  • A letter grade and score for the server's overall posture
  • Is an MCP or agent endpoint exposed, and does it require a login
  • Authorization and OAuth quality, mapped to OWASP MCP risks
  • The tools, resources and prompts a connected AI can reach
  • Known CVEs affecting the server's disclosed software, with fixed versions
  • Deep exposure findings on Pro, each with the fix

How to check an MCP server

There is nothing to install and nothing to configure. A scan takes a few seconds and never touches your data.

1

Enter your domain

Type any domain into the scan box above. We check the domain and the hosts an agent surface usually lives on.

2

We analyze the surface

The scanner discovers the MCP and agent endpoints, then evaluates authentication, authorization, the exposed tools, and hygiene.

3

Review and fix

Read the graded findings, each with what it means and why it matters, and harden what needs it before an agent is turned against you.

Why scan your MCP server

Companies are shipping MCP servers fast to ride the AI wave, and security is racing to catch up. A misconfigured agent endpoint can let an outsider read private data or make a connected AI act against its own user. This scanner tells you where you stand before that happens.

Built for the AI agent era

MCP servers are new, sensitive, and almost nobody scans them. This is purpose-built for that surface, not a generic web scan.

External and non-destructive

Point it at a URL. No install, no credentials, nothing invoked or changed, the same posture as a careful, read-only client.

Mapped to the OWASP MCP Top 10

Every finding is tied to a recognized risk category, so your report lines up with how the industry frames MCP security.

Plain-English, actionable findings

Each result explains what it means and why it matters, in language you can act on and share, without the jargon.

Free to start

See whether your server is exposed and how it scores with no account. Sign in for the full breakdown.

OWASP MCP risks we surface

The OWASP MCP Top 10 is the industry's list of the ways an MCP deployment goes wrong. Our scan maps its externally observable risks so your report speaks the same language as your security team.

RiskWhat it means
Insufficient authenticationAn MCP server that answers tool calls without a valid credential, the single most common and most severe finding.
Token & secret exposureTokens that are not bound to your server, or secrets and files reachable on the same host.
Privilege & scope creepState-changing tools reachable under a broad access grant, letting a connected agent do more than intended.
Tool poisoningManipulated tool definitions that quietly redirect what a connected AI does.
Prompt injectionHidden instructions in server-provided text that hijack the connected model's behavior.
Shadow MCP serversAgent endpoints running on subdomains you may not know are exposed or approved.
Vulnerable components (CVEs)Known CVEs in the MCP software a server discloses, matched against the OSV vulnerability database, with the version that fixes each one.

Frequently asked questions

What is an MCP security scanner?

An MCP security scanner checks the Model Context Protocol surface a website exposes to AI agents. It confirms whether an MCP server exists on your domain, whether it requires authentication, how its authorization is configured, what tools and data it exposes to a connected AI, and whether any of that is misconfigured or over-exposed. SiteSecurityScore runs this externally from a URL, with no install and nothing to bypass.

What is an MCP server?

An MCP (Model Context Protocol) server is an endpoint a company exposes so AI assistants like Claude, ChatGPT and Copilot can securely call its tools and read its data on a user's behalf. It is quickly becoming a standard part of the public web, and because it lets an AI take real actions, it is a new and sensitive attack surface.

Is the MCP scan safe to run?

Yes. The scan is external and non-destructive. It uses the same read-only discovery a normal MCP client uses, reads public metadata, and never attempts to authenticate, bypass a login, invoke a tool, or change any data. You should only run the deeper active checks against a domain you own.

What does the MCP scanner check?

It checks whether an MCP or agent endpoint is exposed, whether tool access requires a credential, the quality of the authorization and login setup, the tools, resources and prompts an AI agent can reach, hidden instructions that could manipulate a connected model, known CVEs in any software the server discloses, and transport and exposure hygiene. Findings are mapped to the OWASP MCP Top 10.

Does the scanner detect known CVEs in an MCP server?

Yes. When an MCP server reveals the software and version it runs, the scanner matches that component against the OSV vulnerability database and reports any known CVEs, each with its severity and the version that fixes it. A server that does not disclose a version cannot be matched from the outside, so a code scan of the source is the way to resolve exact dependencies.

Do I need an account to scan my MCP server?

No account is needed for the essentials: whether a server exists, whether it is authenticated, its overall posture and grade. A free account unlocks the full surface and authorization detail, and a Pro plan adds the deeper active checks.

Scan your MCP server now

See whether your domain exposes an AI agent surface and how it holds up, in seconds, with no account.

Related resources