Agent security & threat detection

Cisco MCP Scanner

Apache-2.0 Python tool from Cisco's AI Defense group that scans MCP servers, their tools, prompts and resources plus server source code, combining YARA rules, LLM-based analysis and Cisco's hosted inspection API, and audits dependencies and bundled binaries. Full detection depth depends on optional third-party services.

open_source · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Agent security & threat detection · Evaluation & testing

Useful conversation with: AppSec engineer, CISO, AI platform lead.

Ask for a demonstration

Show me a scan of an untrusted MCP server package that flags a docstring-versus-implementation mismatch, and which findings required the Cisco AI Defense API.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

The repository states MCP Scanner combines the Cisco AI Defense inspect API, YARA rules and LLM-based analysis to detect malicious MCP tools and can scan tools, prompts, resources and server instructions.

Limit: Detection efficacy is not benchmarked publicly; the inspect API is a Cisco-hosted commercial dependency.

Source s1

Documented by provider

The repository states it scans MCP server source code for behavioural threats, detects mismatches between docstring claims and implementation with cross-file dataflow tracking, audits Python dependencies via pip-audit for CVE/PYSEC/GHSA issues, and hash-checks bundled binaries via VirusTotal.

Limit: VirusTotal and pip-audit are external services; offline coverage and false-positive rates are not documented.

Source s1

Documented by provider

The GitHub repository metadata records an Apache-2.0 license, a non-archived state and commits in September 2026.

Limit: Repository activity does not establish maintenance commitments or release cadence.

Source s2

Limitations to discuss

Sources

  1. cisco-ai-defense/mcp-scanner · Cisco / GitHub · official repository
    Access date reported by researcher: 2026-09-06
  2. GitHub REST API repository record · GitHub · official repository
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction