Item logo image for MCP Install Risk Scanner

MCP Install Risk Scanner

5.0(

1 rating

)
ExtensionDeveloper Tools
Item media 1 (screenshot) for MCP Install Risk Scanner

Overview

Review MCP install commands and config for risky patterns before you run them.

MCP Install Risk Scanner highlights observable setup signals in Model Context Protocol installation commands and configuration snippets. It checks for patterns such as piped shell execution, elevated privileges, destructive commands, sensitive paths, embedded credentials, unpinned runners, insecure endpoints, broad environment access, and privileged containers. Select a command on a page and use the context menu, or open the extension and scan selected or visible setup text. Findings include redacted evidence, remediation guidance, and links to the public methodology. You can export a redacted report as JSON or Markdown for review. All analysis happens locally in the extension. There is no account, upload, telemetry, remote code, advertising, or fetched rule set. The extension requests only activeTab, scripting, and contextMenus. Page access is temporary and follows an explicit user action. A result with no flagged patterns is not proof that a package or server is safe. Static analysis cannot verify publisher identity, package contents, runtime behavior, authorization design, or obfuscated behavior. The scanner is open source under GPLv3. Its deterministic rules, versioned result schema, limitations, examples, and test fixtures are public on GitHub.

Details

  • Version
    0.1.1
  • Updated
    August 8, 2026
  • Size
    45.63KiB
  • Languages
    English
  • Developer
    Wavect GmbH
    Häusern 6 a Ampass 6070 AT
    Website
    Email
    office@wavect.io
    Phone
    +43 650 3056644
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
  • D-U-N-S
    300841315

Privacy

Manage extensions and learn how they're being used in your organization

MCP Install Risk Scanner has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

MCP Install Risk Scanner handles the following:

Authentication information
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps