caglarbozkurt/mcp-heimdall

Security scanner for MCP servers — vet an MCP before you wire it into an agent. Detects prompt-injection, credential exfiltration (via taint analysis), RCE, and supply-chain risks, and catches cross-server exfil chains no single server reveals. Zero-dependency local CLI, SARIF output, CI-gateable, no account.

0Stars on the repository
2Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

heimdall

01

caglarbozkurt/mcp-heimdall

Skill Claude CodeCodex

Vet a Model Context Protocol (MCP) server for safety before installing or connecting it. Use when the user wants to check, audit, scan, or review an MCP server for prompt-injection, data-exfiltration, or malicious capabilities — given a directory, npm package, GitHub repo, or a tools/list JSON dump.

not rated 0 2mo ago A 71 tokens original MIT