# mcpscan

> mcpscan — cognis-digital-mcpscan. Use this tool when you need to identify potential security vulnerabilities in MCP servers, such as RCE, SSRF, no-auth, and tool-poisoning exploits. It scans servers to detect weaknesses, providing outputs that highlight potential risks and inform remediation efforts. Ideal for use in security auditing and penetration testing contexts, mcpscan takes server details as input and returns vulnerability reports.

Canonical page: https://skillsregistry.net/skills/cognis-digital-mcpscan  
JSON: https://api.skillsregistry.net/v1/skills/cognis-digital-mcpscan

## Description

Scan MCP servers for RCE/SSRF/no-auth/tool-poisoning vulnerabilities

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Updated:** 2026-09-21

## Source

- **Source listing:** [GitHub](https://github.com/cognis-digital/mcpscan)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "cognis-digital-mcpscan"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-mcpscan` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-mcpscan/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
