{"repo":"kapilduraphe/mcp-watch","free":true,"listed":false,"github":"https://github.com/kapilduraphe/mcp-watch","clone":"git clone https://github.com/kapilduraphe/mcp-watch.git","description":"A comprehensive security scanner for Model Context Protocol (MCP) servers that detects vulnerabilities and security issues in your MCP server implementations.","language":"TypeScript","stars":135,"topics":["agentic-ai","anthropic","mcp"],"license":"MIT","category":"mcp-servers","readme_excerpt":"MCP Watch 🔍 A comprehensive security scanner for Model Context Protocol (MCP) servers that detects vulnerabilities and security issues in your MCP implementations. Features - 🔑 Credential Detection - Finds hardcoded API keys, tokens, and insecure credential storage - 🧪 Tool Poisoning - Detects hidden malicious instructions in tool descriptions - 🎯 Parameter Injection - Identifies magic parameters that extract sensitive AI context - 💉 Prompt Injection - Scans for prompt manipulation and injection attacks - 🔄 Tool Mutation - Detects dynamic tool changes and rug-pull risks - 💬 Conversation Exfiltration - Finds triggers that steal conversation history - 🎨 ANSI Injection - Detects steganographic attacks using escape sequences - 📋 Protocol Violations - Identifies MCP protocol security violations - 🛡️ Input Validation - Finds command injection, SSRF, and path traversal issues - 🎭 Server Spoofing - Detects servers impersonating popular services - 🌊 Toxic Flows - Identifies dangerous data flow patterns - 🔐 Permission Issues - Finds excessive permissions and access control problems Quick Start 🚀 Option 1: NPM Package (Recommended) Option 2: From GitHub Source Option 3: Docker (No Installation) Installation Global Installation Local Installation From Source Docker Installation 🐳 Quick Start with Docker Docker Compose (Recommended for Production) Docker Features - 🔒 Security : Non-root user, minimal attack surface - 📦 Optimized : Multi-stage builds, Alpine Linux base - ���","default_branch":null,"files":null,"tree":[],"storefront":"/r/kapilduraphe","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/kapilduraphe/mcp-watch/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}