github Python analyzed 283f2f5

cognis-digital/mcpscan

github

Scan MCP servers for RCE/SSRF/no-auth/tool-poisoning vulnerabilities

maintainer
cognis-digital
licence
NOASSERTION
first seen
2026-06-11
last seen
2026-08-19
releases · 30d
0
short id

cognis-digital/mcpscan is an MCP server distributed on github, maintained by cognis-digital, tracked here since June 2026. It has shipped 0 releases and exposes 13 tools. Tools include calc, cleanup, deploy, fetch_url, greet, load_state, and 7 more. Its composite risk grade is C — an inferred review prompt computed from observed signals, not a verdict.

what we found

Reading the source raised one review prompt — dangerous code — each a pattern worth a human look rather than a finding of fault.

Its 13 tools appear to reach filesystem, shell / exec, network and secrets, inferred from tool names, descriptions and input schemas rather than from observed behaviour.

Since the previous scan on 2026-08-19: 2 tools added.

full security breakdown →
tools 13
  • calc
  • cleanup
  • deploy
  • fetch_url
  • greet
  • load_state
  • mcpauth_demo
  • mcpauth_verify
  • proxy_call
  • read_note
  • run_shell
  • safe_echo
  • summarize
release cadence · 90d 0 releases

No releases yet.

recent releases last 0

No releases yet.