{"repo":"TryMightyAI/mighty-security","free":true,"listed":false,"github":"https://github.com/TryMightyAI/mighty-security","clone":"git clone https://github.com/TryMightyAI/mighty-security.git","description":"Don't Simply Trust MCP Server Code, Validate and Scan","language":"Python","stars":97,"topics":[],"license":"MIT","category":"security-tools","readme_excerpt":"MCP Security Scanner Checks if MCP servers are trying to pwn your machine before you install them. The Problem MCP servers can do anything on your computer. Literally anything. We scanned 500+ of them and... yeah, it's bad: - Almost half have command injection bugs - A third will SSRF your internal network - Tons leak files they shouldn't - Remember when GitHub's MCP leaked private repos? That. We built this after getting burned by a malicious MCP server. You probably don't want to learn the hard way. What This Does We catch the obvious stuff - command injection, credential theft, path traversal. Plus the sneaky stuff with ML/LLM analysis. Getting better every day. Installation 💡 New to this? Check out QUICK START.md for detailed setup instructions. Modern Web Dashboard Beautiful React-based security dashboard with real-time monitoring: 🔐 Security Features: - Path traversal protection - Rate limiting (5 local scans / 3 GitHub scans per 5 min) - Input validation & sanitization - URL validation with domain whitelist - Safe error handling (no info disclosure) - Security headers (XSS, clickjacking protection) Dashboard Features: - 🔍 Scanner - Interactive scan mode selection with real-time progress - 📊 Reports - Detailed threat analysis with filtering and export - 📜 History - Complete audit trail of all security actions - ⚡ Tasks - Monitor running scans and task queue - 📚 About - Learn about MCP threats and our protection methods Beautiful UI: - Glass morphism effects and ne","default_branch":null,"files":null,"tree":[],"storefront":"/r/TryMightyAI","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/TryMightyAI/mighty-security/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}