Security-First Trust Registry · npm · CLI

Scan MCP Servers
for Vulnerabilities

Vigile checks MCP servers for tool poisoning, data exfiltration, permission abuse, and obfuscation — before they reach your machine. Free trust scores for every server in the ecosystem.

Free. No account required. 200+ detection checks across the Vigile engine.

Install

Three ways to scan MCP servers

01

CLI Scanner

npx vigile-scan --all

Scans all MCP server configs on your machine. Finds Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, and OpenClaw configurations automatically.

02

MCP Server

npx vigile-mcp

Add Vigile as an MCP server in Claude Code or Cursor. Query trust scores and scan servers directly from your AI agent.

03

Web Scanner

vigile.dev/scan-server

Paste a server name or URL into the web scanner for instant analysis. No install needed.

Detection

MCP-specific threat patterns

🎯TP-001

Tool Poisoning

Hidden instructions in tool descriptions that hijack agent behavior without user knowledge.

📤EX-003

Data Exfiltration

Patterns targeting SSH keys, AWS credentials, .env files, and browser cookies.

🔓PM-001

Permission Abuse

Excessive filesystem, network, or code execution access beyond stated purpose.

🔮OB-002

Obfuscation

Base64 encoding, hex payloads, zero-width characters hiding malicious content.

Plus typosquatting detection and Sentinel runtime phone-home detection.

Trust Scores

Every MCP server gets a score

Vigile assigns a 0–100 trust score based on five weighted factors: code analysis (30%), dependency health (20%), permission safety (20%), behavioral stability (15%), and transparency (15%).

Search the trust registry →

cursor-mcp

Trusted

94

web-scraper-mcp

Moderate

67

crypto-helper-mcp

Dangerous

23

For MCP Authors

Add a trust badge to your README

Show users your server is safe. The badge updates automatically when your trust score changes.

[![Vigile Trust Score](https://api.vigile.dev/badge/your-server-name)](https://vigile.dev/server/your-server-name)

Don't install MCP servers blind.

Scan before you install. Check trust scores. Monitor runtime behavior. Vigile is free for individual developers.