$git clone https://github.com/sahiloj/MCPScan
Installs into the current project.
Summary
Offensive MCP server auditor: detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.