Cisco MCP Scanner
Major vendor backing (Cisco) gives enterprise credibility. Detects tool poisoning, rug pull attacks, and over-privileged permissions. Customizable YARA rules.
Enterprise-grade MCP server security scanner combining Cisco AI Defense inspect API, YARA rules, and LLM-as-a-judge to detect malicious MCP tools. CLI and REST API modes.
- Scan all MCP servers for tool poisoning and rug pull attacks
- Add custom YARA rules to detect organization-specific threat patterns
- Run production readiness assessments on MCP server configurations
Major vendor backing (Cisco) gives enterprise credibility. Detects tool poisoning, rug pull attacks, and over-privileged permissions. Customizable YARA rules.
Enterprise security teams scanning MCP server deployments for threats.
https://github.com/cisco-ai-defense/mcp-scanner
By Cisco AI Defense
How to Get It
uv tool install --python 3.13 cisco-ai-mcp-scanner
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
After installing, paste this into Claude:
Help me scan all MCP servers for tool poisoning and rug pull attacks
Trust Signals Auto-scanned
Data & Access
Community Pulse Active
Discussed on Hacker News, Reddit
- MCP-Scanner – Scan MCP Servers for vulnerabilities — Hacker News · 168 pts
- MCP servers are the new attack surface – so I mapped it and built a scanner — Reddit · 51 pts
- Cisco Released MCP Scanner for finding security threats in MCP servers — Reddit · 34 pts
3 mentions across 2 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 979 GitHub stars; 25 contributors; last commit 8d ago; license Apache-2.0.
Things to check
- Effectiveness depends on YARA rule currency and LLM-as-judge calibration; zero-day MCP exploits may not be detected. Requires integration effort for REST API or CLI into existing security workflows.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 979 GitHub stars; 25 contributors; last commit 8d ago; license Apache-2.0.