MCP-Defender/MCP-Defender

View on GitHub ↗

Desktop app that automatically scans and blocks malicious MCP traffic in AI apps like Cursor, Claude, VS Code and Windsurf.

255 ★43 forksTypeScriptUpdated 3mo ago

What you need to know

An MCP server that scans your existing MCP servers and machines to detect exposed secrets, prompt injection, beginner mistakes, and server-side request forgery vulnerabilities.

Install

Configure MCP-Defender as an MCP client and point it at the MCP servers you want to audit

Usage

  • Ask the assistant to scan a configured MCP server for security issues

Key features

  • Detects exposed secrets and prompt injection risks
  • Flags beginner mistakes in MCP server configuration
  • Detects server-side request forgery (SSRF) vulnerabilities

Best for

Developers who want a security audit pass over their MCP servers before exposing them to agents.

Clients: MCP clients

Reviewed 2026-08-11

Topics

ai-toolsmcpmcp-clientmcp-client-securitymcp-securitymcp-servermcp-toolsmodel-context-protocol
Stars
255★
Forks
43
Language
TypeScript
License
AGPL-3.0
Created
2025-05-28
Last push
2026-06-05