Browse
→ Infrastructure
→ mcphound
mcphound
Independent security scanner and reputation layer for MCP servers and agent skills. The v0.1 release discovers configured MCP servers across agent clients, performs static supply-chain checks, emits SARIF, supports policy enforcement, and never executes scanned servers during static analysis. Public GitHub repository created August 28, 2026.
MCP unverified
Integration
| Transport | stdio |
| Auth | none |
| Endpoint | uvx mcphound scan |
| Install | uvx mcphound scan |
Use Cases
| 01 | Scan local MCP configurations for hardcoded secrets, risky launch commands, and over-broad filesystem access |
| 02 | Enforce mcp-policy.yaml in CI and emit SARIF for pull-request security review |
| 03 | Build a reputation database from scanned MCP registry entries and per-server risk history |
Tags
security mcp-security supply-chain sarif policy scanner reputation python
Machine-readable: /api/servers.json
· JSON-LD schema embedded in <head>