{"repo":"riseandignite/mcp-shield","free":true,"listed":false,"github":"https://github.com/riseandignite/mcp-shield","clone":"git clone https://github.com/riseandignite/mcp-shield.git","description":"Security scanner for MCP servers","language":"TypeScript","stars":555,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"MCP-Shield MCP-Shield scans your installed MCP (Model Context Protocol) servers and detects vulnerabilities like tool poisoning attacks, exfiltration channels and cross-origin escalations. Usage Run default scan: With Claude API key for enhanced analysis: With a specific config file: With the --identify-as flag: Get help: With a safe list of servers to exclude from scanning: Options: - --path : Scan a specific path for MCP configuration files ( .mcp/ .json , claude desktop config.json ). If omitted, scans standard locations ( /.config/.mcp , /Library/Application Support/Claude , /.continue ). - --claude-api-key : (Optional) Provide an Anthropic Claude API key for enhanced vulnerability analysis using AI. - --identify-as : (Optional) Identify as a different client name (e.g., claude-desktop ) when connecting to servers. Useful for testing if servers behave differently based on the client ID (potential bait-and-switch). - --safe-list : (Optional) Comma-separated list of server names to exclude from scanning. These servers will be skipped and also excluded from cross-origin violation detection. - -h, --help : Display help information. Output Example Features - 🛡️ Vulnerability Detection : - Hidden instructions in tool descriptions - Potential data exfiltration channels - Tool shadowing and behavior modification - Sensitive file access attempts - Cross-origin violations between servers - 📄 Config File Support : Cursor, Claude Desktop, Windsurf, VSCode, Codeium - 🧠 Optional Cla","default_branch":null,"files":null,"tree":[],"storefront":"/r/riseandignite","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/riseandignite/mcp-shield/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}