{"repo":"MCP-Audit/MCTS","free":true,"listed":false,"github":"https://github.com/MCP-Audit/MCTS","clone":"git clone https://github.com/MCP-Audit/MCTS.git","description":"MCTS (Model Context Threat Scanner) is a local-first security scanner for MCP servers -- static and live tool discovery, multiple analyzers, auditable risk scores, and JSON, SARIF, and HTML output. For authors and platform teams; CI-ready, no cloud API.","language":"Python","stars":28,"topics":["ai-agents","ai-agents-security","ai-safety","mcp","mcp-audit","mcp-security-testing","mcp-server","model-context-protocol","security","starify"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"MCTS Model Context Threat Scanner Security scanner for Model Context Protocol (MCP) servers — the programs that give AI assistants access to tools, files, databases, and APIs. Run one command to find permission issues, injection risks, attack chains, and more. Works locally, in CI, with no cloud account required. New to MCP or MCTS? See the documentation index and glossary. Demo Scan the included vulnerable MCP server: Example terminal output Two scores on one scan is normal — see the scoring developer guide. Problem AI assistants connect to the outside world through MCP servers — small programs that expose callable tools (e.g. \"delete user\", \"read file\", \"query database\"). A misconfigured or malicious server can: - Grant the AI destructive capabilities it shouldn't have - Hide malicious instructions in tool descriptions - Chain innocent tools into data theft or remote code execution - Leak secrets embedded in server source code Most teams ship MCP servers without dedicated security review. MCTS makes scanning as routine as running a linter. Features MCTS is alpha software with a local-first MCP security pipeline — no cloud account required for standard scans. Full reference: Security checks · CLI. Scanning & discovery Capability How ------------ ----- Repository & entrypoint scan mcts scan ./repo/ or mcts scan ./server.py — Python + TypeScript static discovery Auto target resolution mcts scan . --auto — pick entrypoint or lone MCP config server Multi-surface analysis --surfa","default_branch":null,"files":null,"tree":[],"storefront":"/r/MCP-Audit","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/MCP-Audit/MCTS/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}