loaditout.ai
SkillsPacksTrendingLeaderboardAPI DocsBlogSubmitRequestsCompareAgentsXPrivacyDisclaimer
{}loaditout.ai
Skills & MCPPacksBlog

mcp-scan-action

MCP Tool

nhomyk/mcp-scan-action

The first GitHub Action that scans MCP servers, AI agents & LLM pipelines for security vulnerabilities. 24 checks: tool poisoning, SSRF, prompt injection, DataFlow taint. Results in GitHub Security tab via SARIF. No API key required.

Install

$ npx loaditout add nhomyk/mcp-scan-action

Platform-specific configuration:

.claude/settings.json
{
  "mcpServers": {
    "mcp-scan-action": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-scan-action"
      ]
    }
  }
}

Add the config above to .claude/settings.json under the mcpServers key.

Tags

agenticqaai-agentsai-securitycode-scanningdevsecopsgithub-actionsllm-securitymcpmodel-context-protocolprompt-injectionsarifsecurityssrfstatic-analysis

Reviews

Loading reviews...

Quality Signals

2
Stars
0
Installs
Last updated48 days ago
Security: B

Safety

Risk Levelmedium
Data Access
read
Network Accessnone

Details

Sourcegithub-crawl
Last commit3/3/2026
View on GitHub→

Embed Badge

[![Loaditout](https://loaditout.ai/api/badge/nhomyk/mcp-scan-action)](https://loaditout.ai/skills/nhomyk/mcp-scan-action)