# mcp-security-scanner

> mcp-security-scanner — hailbytes-mcp-security-scanner. Use this tool when you need to identify security vulnerabilities in Model Context Protocol (MCP) server configurations, such as overprivileged tools or missing authentication. It scans configurations to detect common security issues, including prompt injection surfaces and unsafe defaults, and provides outputs to help remediate these problems. Ideal for use in git-based development workflows to ensure secure MCP server setups.

Canonical page: https://skillsregistry.net/skills/hailbytes-mcp-security-scanner  
JSON: https://api.skillsregistry.net/v1/skills/hailbytes-mcp-security-scanner

## Description

Scans Model Context Protocol (MCP) server configurations for common security issues: overprivileged tools, missing auth, prompt injection surface, unsafe defaults.

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** scanned
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Category:** ai-ml
- **Updated:** 2026-09-21

## Source

- **Source listing:** [GitHub](https://github.com/HailBytes/mcp-security-scanner)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "hailbytes-mcp-security-scanner"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/hailbytes-mcp-security-scanner` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/hailbytes-mcp-security-scanner/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
