# mcp-scan

> mcp-scan — chris79og-mcp-scan. Use this tool when you need to identify security vulnerabilities in MCP servers, as it detects potential threats and generates SARIF reports to help mitigate risks. It takes MCP server configurations as input and produces detailed security reports as output. Ideal for use in development and deployment pipelines, such as git workflows, to ensure server security and compliance.

Canonical page: https://skillsregistry.net/skills/chris79og-mcp-scan  
JSON: https://api.skillsregistry.net/v1/skills/chris79og-mcp-scan

## Description

MCP server security scanner — detects vulnerability patterns, outputs SARIF reports

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Category:** security
- **Updated:** 2026-09-21

## Source

- **Source listing:** [GitHub](https://github.com/Chris79OG/mcp-scan)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "chris79og-mcp-scan"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/chris79og-mcp-scan` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/chris79og-mcp-scan/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
