caglarbozkurt/mcp-heimdall

Security scanner for MCP servers — vet an MCP before you wire it into an agent. Detects prompt-injection, credential exfiltration (via taint analysis), RCE, and supply-chain risks, and catches cross-server exfil chains no single server reveals. Zero-dependency local CLI, SARIF output, CI-gateable, no account.

0Stars on the repository
2Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

heimdall

01

caglarbozkurt/mcp-heimdall

MCP server Claude CodeCodexCursor +2

Scan an MCP server or agent config for injection, exfiltration, and risky capabilities. Runs locally from the mcp-heimdall-scan npm package.

not rated 0 2mo ago A tokens not measured original MIT