MCP Security Scanner
Paste any public GitHub repository URL to score it live with the same 15-signal methodology used across the directory. This is a trust signal, not a security audit — see the methodology for what it does and doesn't catch.
The scan checks real repository facts — maintenance activity, license, whether the vendor is the official maintainer, whether any tool requests dangerous permissions (execute, delete, write access), and whether a read-only mode exists — the same checks behind every score in the directory. Works on any public MCP repository, listed here or not; nothing you scan is stored.