Scan MCP servers for RCE/SSRF/no-auth/tool-poisoning vulnerabilities
cognis-digital/mcpscan is an MCP server distributed on github, maintained by cognis-digital, tracked here since June 2026. It has shipped 0 releases and exposes 13 tools. Tools include calc, cleanup, deploy, fetch_url, greet, load_state, and 7 more. Its composite risk grade is C — an inferred review prompt computed from observed signals, not a verdict.
Reading the source raised one review prompt — dangerous code — each a pattern worth a human look rather than a finding of fault.
Since the previous scan on 2026-08-19: 2 tools added.
full security breakdown →-
calc -
cleanup -
deploy -
fetch_url -
greet -
load_state -
mcpauth_demo -
mcpauth_verify -
proxy_call -
read_note -
run_shell -
safe_echo -
summarize
No releases yet.
No releases yet.