MCP servers let AI access your files, APIs, and databases. But are they safe? MCPSafe scans for SQL injection, code execution, and hardcoded secrets before you install. We've found 1,200+ vulnerabilities across 300 servers. Free and open-source.
No reviews yetBe the first to leave a review for MCPSafe
Maker
π
Hey Product Hunt! π
We built MCPSafe after a scary realization: developers are installing MCP servers that give Claude/ChatGPT direct access to their filesystems, databases, and shell... without ever auditing the code.
So we scanned 306 public MCP servers (so far...). We found:
- 69 critical vulnerabilities (remote code execution, SQL injection)
- 32 servers with hardcoded API credentials
- 10% of servers with security scores below 50
The MCP ecosystem is amazing, but it's also the Wild West right now.
MCPSafe gives you:
β Instant security scores for any MCP server
β Detailed vulnerability reports with fix suggestions
β Watchlist alerts when servers you use get compromised
We want the MCP ecosystem to grow β securely. Would love your feedback!
ChatPal
Congrats! Is this for builders creating MCP or for users to make sure MCPs they use are safe?
@daniele_packardΒ Both! users can scan any servers they want, and builders can add a security badge to their servers so users can see how secure it is