
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
mcpshield-cli
Advanced tools
Scan MCP servers and GitHub repositories for security vulnerabilities.
Powered by MCPShield — the MCP security scanner with 59+ detection rules covering the OWASP MCP Top 10.
npm install -g mcpshield
Get a free API key at mcpshield.co/settings, then:
mcpshield auth mcp_sk_your_key_here
# Scan an HTTP MCP server
mcpshield scan --url https://mcp-server.example.com/mcp
# Scan a GitHub repository
mcpshield scan --github https://github.com/user/repo
# JSON output (for CI/CD)
mcpshield scan --url https://mcp-server.example.com/mcp --json
# Filter by severity
mcpshield scan --url https://mcp-server.example.com/mcp --severity high
0 — Scan completed, no critical findings1 — Error (invalid key, rate limit, scan failure)2 — Scan completed with critical findingsMCPSHIELD_API_KEY — API key (alternative to mcpshield auth)MCPSHIELD_API_URL — Custom API endpoint (for self-hosted)MIT
FAQs
MCPShield CLI — Scan MCP servers for security vulnerabilities
The npm package mcpshield-cli receives a total of 28 weekly downloads. As such, mcpshield-cli popularity was classified as not popular.
We found that mcpshield-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.