mcp-scanner

Evaluate MCP tools for security, functionality, and license compliance.

29|2|Updated Jan 11, 2026
One-click install
npx skills add https://github.com/jbdamask/john-claude-skills --skill mcp-scanner
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mcp-scanner
Source: https://github.com/jbdamask/john-claude-skills/tree/main/skills/mcp-scanner
Command: npx skills add https://github.com/jbdamask/john-claude-skills --skill mcp-scanner

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps users understand the safety, functionality, and legal implications of Model Context Protocol (MCP) tools before they install them, preventing potential security risks and ensuring the tool meets their needs.

Core Features & Use Cases

  • Safety Assessment: Analyzes MCP servers for security vulnerabilities (e.g., hardcoded secrets, command injection).
  • Functionality Review: Checks if the MCP tool does what the user expects and identifies limitations.
  • License Compliance: Evaluates the MCP's license for commercial use restrictions and sharing requirements.
  • Use Case: A developer wants to integrate a new MCP tool found on GitHub. They provide the URL, and this Skill performs a comprehensive review, delivering a plain-language report on its safety, functionality, and licensing, along with a clear recommendation.

Quick Start

Use the mcp-scanner skill to assess the MCP tool at https://github.com/example/mcp-tool.

Frequently Asked Questions about mcp-scanner

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I evaluate MCP tool safety before installing it from a GitHub repository?

To evaluate MCP tool safety, fetch the source code from the repository URL and analyze it against a security checklist to identify vulnerabilities like hardcoded secrets or command injection before installation.

What security risks should I check for when reviewing Model Context Protocol servers?

When reviewing Model Context Protocol servers, check for security vulnerabilities such as hardcoded secrets and command injection by scanning the source code to ensure safe integration.

How can I check if an MCP tool's license allows commercial use?

To check if an MCP tool's license allows commercial use, perform a license compliance analysis on the repository to evaluate sharing requirements and commercial use restrictions before integration.

Can I assess the functionality and limitations of an MCP tool before adding it to my environment?

Yes, you can assess MCP tool functionality by scanning the repository URL to check if the tool meets your expectations and to identify any operational limitations before installation.

What is the best way to perform a risk assessment on an npm MCP package?

The best way to perform a risk assessment on an npm MCP package is to fetch its source code and analyze it for security vulnerabilities, functionality gaps, and legal compliance.

Does MCP tool evaluation provide plain-language reports or technical details?

MCP tool evaluation provides plain-language reports summarizing safety, functionality, and licensing, with deeper technical details available on request for comprehensive risk assessment.