1. Conduid
  2. Social
  3. MCPAmpel - MCP Security Scanner
MCP server · Social

MCPAmpel - MCP Security Scanner

Scan installed MCP servers for security vulnerabilities with 16 detection engines.

Unclaimed social
37Low

Scored 5 months ago · breakdown

About MCPAmpel - MCP Security Scanner

MCPAmpel - MCP Security Scanner is an MCP server in the Social category: scan installed MCP servers for security vulnerabilities with 16 detection engines. It has been installed 0 times through Conduid.

Install

uvx
uvx mcpampel
pip
pip install mcpampel

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about MCPAmpel - MCP Security Scanner

Powered by Claude · Grounded in docs

I know everything about MCPAmpel - MCP Security Scanner. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • ·Scoped permissionsNot checked yet.

README

MCPAmpel - MCP Security Scanner

MCPAmpel

Scan your installed MCP servers for security vulnerabilities, directly from your AI agent.

MCPAmpel discovers MCP servers from your Claude Code, Cursor, Windsurf, or Gemini CLI configuration, submits them to 16 scanning engines, and returns an aggregated trust score with detailed findings.

50 API calls/day included.

Quick Start

uvx mcpampel

Configuration

Claude Code / Claude Desktop

Add to ~/.claude/settings.json or claude_desktop_config.json:

{
  "mcpServers": {
    "mcpampel": {
      "command": "uvx",
      "args": ["mcpampel"],
      "env": {
        "MCPAMPEL_API_KEY": "your_key_here"
      }
    }
  }
}

Cursor

Add to ~/.cursor/mcp.json:

{
  "mcpServers": {
    "mcpampel": {
      "command": "uvx",
      "args": ["mcpampel"],
      "env": {
        "MCPAMPEL_API_KEY": "your_key_here"
      }
    }
  }
}

Windsurf

Add to ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "mcpampel": {
      "command": "uvx",
      "args": ["mcpampel"],
      "env": {
        "MCPAMPEL_API_KEY": "your_key_here"
      }
    }
  }
}

Gemini CLI

Add to ~/.gemini/settings.json:

{
  "mcpServers": {
    "mcpampel": {
      "command": "uvx",
      "args": ["mcpampel"],
      "env": {
        "MCPAMPEL_API_KEY": "your_key_here"
      }
    }
  }
}

Getting an API Key

Register for free at mcpampel.com.

Environment Variables

Variable Required Default Description
MCPAMPEL_API_KEY Yes - Your API key (free at mcpampel.com)
MCPAMPEL_BASE_URL No https://mcpampel.com API base URL

Tools

scan_my_servers

Discovers all MCP servers from your editor config and scans them with 16 engines. Returns a summary table with trust scores. No input needed.

scan_url

Scan a single GitHub, GitLab, npm, or PyPI URL. Returns trust score, engine breakdown, and findings.

Parameter Type Required
url string Yes

check_status

Show your daily quota usage and remaining scans.

get_scan_results

Get detailed results for a specific scan by ID. Use after scan_my_servers or scan_url to drill into findings.

Parameter Type Required
scan_id string Yes

Development

cd mcp-plugin
uv sync
uv run pytest

License

Apache License 2.0


mcpampel.com

README mirrored from the source repository 5 months ago. The original is authoritative.

Questions

About MCPAmpel - MCP Security Scanner

How do I install MCPAmpel - MCP Security Scanner?

Run uvx mcpampel, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is MCPAmpel - MCP Security Scanner safe to use with an AI agent?

Its trust score is 37 out of 100 (low). Conduid hasn't run static security checks on this repository yet, so review the source yourself before granting it credentials. It has no ConduID identity yet, so agent calls to it are not receipted.

Is MCPAmpel - MCP Security Scanner still maintained?

Conduid hasn't recorded a commit date for this repository yet. Check the repository directly for recent activity.