MCPs โบ Security โบ Compuute MCP Security Scanner
Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back. 37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin โ every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning). This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output โ triage is on you, and the response says so explicitly. POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review. Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.
Not monetized yet
Turn Compuute MCP Security Scannerโs tool calls into revenue: one disclosed sponsored slot, 70% revenue share, fail-open by design.
Install Compuute MCP Security Scanner
For anyone using Compuute MCP Security Scanner โ no Lulu account needednpx -y @smithery/cli@latest install daniel-abbay/compuute-scan-api --client claude
Real-time weather for any city, built on the lulu-ads widget gallery. First-party, free forever.
View server โFAQ
Compuute MCP Security Scanner installs from source โ follow the repository README.
22 out of 100, computed from cross-registry traction signals (installs, stars, registry presence) โ never influenced by sponsorship.
Works well together