Complete AI Training

MCP server · Security

mcp-shield security scanner

by muhannad-hash

Let your AI check an MCP server or npm package for hidden dangers before you trust it.

Flow diagram: you ask your AI “Is this npm package safe to install?”, on your own computer the mcp-shield security scanner works with your own computer, and you get back A short safety report.

mcp-shield is a safety checker for MCP servers. It looks inside a server's code and tells you if something looks sneaky, like sending your passwords somewhere or running hidden commands. It is handy if you like trying new AI add-ons but want to know they are safe first.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to an app. This one gives your AI the skill of checking other MCP servers for danger. So instead of you reading code yourself, you ask your AI and it does the checking for you.

What this MCP server does

You ask your AI to look at a server or a package from npm. Your AI uses mcp-shield, which downloads or reads the code and looks for known bad patterns. It checks things like secret keys being sent over the internet, hidden commands, scrambled code, and sneaky instructions aimed at fooling an AI. Then it gives you a clear verdict with a list of what it found. It can also check how trustworthy a package is based on how old it is and how many people use it.

Flow diagram: you ask your AI “Is this npm package safe to install?”, on your own computer the mcp-shield security scanner works with your own computer, and you get back A short safety report. Click to zoom

What you can do with it

  • Scan an npm package before you install it
  • Scan a folder on your computer where you cloned a server
  • Check a piece of text for hidden prompt injection tricks
  • Get a trust score and known issues for any npm package
  • See a list of problems ranked by how serious they are
  • Audit several MCP servers you already have installed

Try asking your AI

  • “Scan the npm package some-sketchy-mcp-server before I install it”
  • “Scan the MCP server I cloned at ~/projects/some-mcp”
  • “Check this tool description for prompt injection: paste text here”
  • “What is the trust score for popular-mcp-tool on npm?”

What it gives back to you

You get a short report in the chat with a verdict like SAFE, RISKY, or DANGEROUS. Under that, it lists each problem it found, the file and line number, and a short note about why it matters. For npm packages, you also get a small table with the package age, weekly downloads, and a trust score out of 100.

Before you start

What you need

  • The Claude desktop app or another AI tool that supports MCP servers
  • Node.js installed on your computer (the free program that runs these helpers)
  • Internet access if you want to scan packages from npm

Good to know

It reads the code of servers and packages you point it at, so only scan things you are allowed to look at, and remember a clean scan is not a guarantee of safety.

Install it with your AI

Add mcp-shield security scanner to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check mcp-shield security scanner, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Anyone who likes trying new AI add-ons and wants a quick safety check before trusting them, especially people who are not coders.