Atlas / MCP servers / invariantlabs-ai / MCP Scan

MCP ScanBLOCK

mcp/invariantlabs-ai/mcp-scan

Security scanner for AI agents, MCP servers and agent skills.

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
19 14r · 4w · 1d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
3,080
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Snyk Agent Scan

Discover and scan agent components on your machine for prompt injections and vulnerabilities (including agents, MCP servers, skills).

Note: We don't publish an npm package for Agent Scan. Install it via uvx or as a standalone binary.
Note: CLI output is experimental and subject to change Agent Scan v0.5.x (planned for deprecation) The raw output of this CLI — including issue codes, field names, severity labels, and response structure — is experimental and may change without notice between releases. We do not recommend building production workflows that depend on specific CLI output fields or issue codes. Agent Scan v0.6 and later The raw output of this CLI — including risk indicator names, scores, field names, and response structure — is experimental and may change without notice between releases. We do not recommend building production workflows that depend on specific CLI output fields or risk names. If you are an enterprise customer using Snyk to manage agent security risk at scale, the CLI output may not reflect what is sent to and shown in the Evo platform. The underlying integration, discovery, and risk assessment that powers enterprise deployments is stable and supported — any changes will be communicated in line with standard Snyk product practices. Contact your account team for deployment guidance.
NEW Read our technical report on the emerging threats of the agent skill eco-system published together with Agent Scan 0.4, which adds support for scanning agent skills.
Read from source at commit d97a3951b409OBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add snyk-agent-scan --env PUSH_KEY=${PUSH_KEY} --env SNYK_TOKEN=${SNYK_TOKEN} -- uvx snyk-agent-scan
claude-desktop
{
  "mcpServers": {
    "snyk-agent-scan": {
      "command": "uvx",
      "args": [
        "snyk-agent-scan"
      ],
      "env": {
        "PUSH_KEY": "${PUSH_KEY}",
        "SNYK_TOKEN": "${SNYK_TOKEN}"
      }
    }
  }
}
03

Exposed tools (19)

14 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addwritereturn a + b
browser_closereadClose the page
create_pull_requestwrited
delete_filedestructive
dividereadDivide two numbers.
gcdreadCalculate the greatest common divisor (GCD) of two integers.
get_api_keyread
get_commentsread
get_connectionsreadreturn [
get_current_timeread
get_train_inforeadGet information about a train.
is_primereadReturn True if n is a prime number, False otherwise.
lcmreadCalculate the least common multiple (LCM) of two integers.
multiplyread
send_emailwrite
store_valuereadStore here all important values!
subtractreadSubtract two numbers.
sumwriteAdd two numbers together.
weatherreadGet current weather for a location.
04

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/agent_scan/well_known_clients.py:123
client_exists_paths=["~/.aws/amazonq"],
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/agent_scan/well_known_clients.py:125
"~/.aws/amazonq/agents/default.json",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/agent_scan/well_known_clients.py:126
"~/.aws/amazonq/agents/mcp.json",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/agent_scan/well_known_clients.py:127
"~/.aws/amazonq/mcp.json",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/agent_scan/well_known_clients.py:220
client_exists_paths=["~/.aws/amazonq"],
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_verify_api.py:1520
secret = "ghp_abcdefghijklmnopqrstuvwxyz1234567890"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_verify_api.py:1569
secret = "ghp_abcdefghijklmnopqrstuvwxyz1234567890"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/unit/test_verify_api.py:1520
secret = "ghp_abcdefghijklmnopqrstuvwxyz1234567890"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/unit/test_verify_api.py:1569
secret = "ghp_abcdefghijklmnopqrstuvwxyz1234567890"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
tests/unit/test_redact_prefilter_equivalence.py:23
"xoxb-123456789012-1234567890123-" + "abcdefghijklmnopqrstuvwx",  # Slack
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/agent_scan/traffic_capture.py:65
digest = hashlib.sha1(key, usedforsecurity=False).digest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_agent_discovery.py:1294
["relative/plugin", "../../etc", "~", "~/", "~/../../etc", "~root/.ssh", "/Users", "/home"],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_agent_discovery.py:4790
'[{"relativeLocation": "pub.good-1.0.0"}, {"relativeLocation": "../../outside"}]'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_agent_discovery.py:11039
"../../../etc",
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_mcp_destination_guard.py:31
["169.254.169.254", "169.254.0.1", "fe80::1", "febf::1", "fd00:ec2::254", "100.100.100.200"],
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_mcp_destination_guard.py:48
@pytest.mark.parametrize("host", ["169.254.169.254", "2852039166", "025177524776", "[::ffff:169.254.169.254]"])
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_mcp_destination_guard.py:77
@pytest.mark.parametrize("addresses", [("127.0.0.1", "169.254.169.254"), ("fe80::1", "::1")])
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_mcp_destination_guard.py:95
AsyncMock(side_effect=[resolved("127.0.0.1"), resolved("169.254.169.254")]),
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_mcp_destination_guard.py:115
("metadata-server", RemoteServer(url="http://169.254.169.254/mcp")),
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2e/test_guard_install.py:44
yield f"http://127.0.0.1:{port}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2e/test_inspect.py:71
yield f"http://127.0.0.1:{server.server_port}/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2e/test_inspect.py:83
yield f"http://127.0.0.1:{server.server_port}/mcp"

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha d97a3951b409full audit observations/trust-audit/mcp-server/invariantlabs-ai__mcp-scan.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-24d97a3951b409BLOCKD61first audit
06

Questions

What is the MCP Scan MCP server?

Security scanner for AI agents, MCP servers and agent skills.

What tools does MCP Scan expose?

19 in total: 14 read-only, 4 that write, and 1 that can delete or overwrite (delete_file). Every one is listed on this page with its risk.

Is MCP Scan safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MCP Scan need?

It reads PUSH_KEY and SNYK_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MCP Scan run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as snyk-agent-scan.

How current is this page?

The grade is for one exact copy of the source (d97a3951b409), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement