BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Cisco MCP Scanner

Skill Security Solid
Works inClaude Code
Solid Scanned — metadata only

Major vendor backing (Cisco) gives enterprise credibility. Detects tool poisoning, rug pull attacks, and over-privileged permissions. Customizable YARA rules.

Enterprise-grade MCP server security scanner combining Cisco AI Defense inspect API, YARA rules, and LLM-as-a-judge to detect malicious MCP tools. CLI and REST API modes.

987 starsApache-2.0 (commercial OK)FreeQuick setup
Official tool maintained by Cisco AI Defense.

Major vendor backing (Cisco) gives enterprise credibility. Detects tool poisoning, rug pull attacks, and over-privileged permissions. Customizable YARA rules.

Enterprise security teams scanning MCP server deployments for threats.

Claude Code Claude Cowork Claude Chat

https://github.com/cisco-ai-defense/mcp-scanner

By Cisco AI Defense

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
uv tool install --python 3.13 cisco-ai-mcp-scanner

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me scan all MCP servers for tool poisoning and rug pull attacks
PrerequisitesPython 3.11+ and uv; optional Cisco AI Defense API key, an LLM provider API key, and a VirusTotal API key for the respective scanning engines.CostFree

Trust Signals Auto-scanned

Stars987Contributors26Last updated2026-07-16LicenseApache-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-19 · scanner v1

Data & Access

Connects toCisco AI Defense servers (official integration)

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 2 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 979 GitHub stars; 25 contributors; last commit 8d ago; license Apache-2.0.

Things to check

  • Effectiveness depends on YARA rule currency and LLM-as-judge calibration; zero-day MCP exploits may not be detected. Requires integration effort for REST API or CLI into existing security workflows.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
4/5
Versatility
4/5
Reliability
5/5
Security
4/5
Overall score4.25 / 5.00 SolidEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 979 GitHub stars; 25 contributors; last commit 8d ago; license Apache-2.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →