
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
mcpshield-cli
Advanced tools
Scan MCP servers and GitHub repositories for security vulnerabilities.
Powered by MCPShield — the MCP security scanner with 59+ detection rules covering the OWASP MCP Top 10.
npm install -g mcpshield
Get a free API key at mcpshield.co/settings, then:
mcpshield auth mcp_sk_your_key_here
# Scan an HTTP MCP server
mcpshield scan --url https://mcp-server.example.com/mcp
# Scan a GitHub repository
mcpshield scan --github https://github.com/user/repo
# JSON output (for CI/CD)
mcpshield scan --url https://mcp-server.example.com/mcp --json
# Filter by severity
mcpshield scan --url https://mcp-server.example.com/mcp --severity high
0 — Scan completed, no critical findings1 — Error (invalid key, rate limit, scan failure)2 — Scan completed with critical findingsMCPSHIELD_API_KEY — API key (alternative to mcpshield auth)MCPSHIELD_API_URL — Custom API endpoint (for self-hosted)MIT
FAQs
MCPShield CLI — Scan MCP servers for security vulnerabilities
The npm package mcpshield-cli receives a total of 28 weekly downloads. As such, mcpshield-cli popularity was classified as not popular.
We found that mcpshield-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.