MCP security scanners compared

Several open-source tools now scan MCP servers for poisoned tools and risky configurations. They differ most in how they detect (patterns, LLMs or a hosted API), what they send off your machine, and what happens after the first scan.

Checked against each project’s own README on 30 September 2026. Projects move quickly: “not documented” means we could not find it in their docs, not that it cannot exist. Spotted something out of date? Open an issue and we will fix it.

HecateSnyk Agent ScanCisco MCP ScannerProximity
Formerlyn/aInvariant Labs mcp-scann/an/a
RuntimeNode.js 20+Python, or a standalone binaryPython 3.11+Python 3.10+
Installnpx hecate-mcp@betauvx snyk-agent-scan@latestuv tool install cisco-ai-mcp-scannerclone, pip install -r requirements.txt
LicenseApache-2.0Apache-2.0Apache-2.0GPL-3.0
DetectionDeterministic rulesLocal checks plus the Agent Scan APIYARA rules; optional LLM, Cisco AI Defense API and VirusTotal enginesDiscovery; NOVA rules with LLM evaluation for security analysis
Tool definitions leave your machineNeverYes: tool names, descriptions and configs go to the API (secrets redacted)Only with the LLM or API enginesOnly with LLM evaluation
Rug pulls: pin approved definitions, check in CIYes (pin, check, committed lockfile)Not documentedNot documentedNot documented
Cross-server analysisLethal trifecta and shadowing across all of an agent’s serversToxic flows, tool shadowingNot documentedNot documented
SARIF for code scanningYesNot documented (JSON, CI mode)Not documented (JSON and other formats)Not documented (JSON, Markdown)
Runtime guardYes: @hecate-mcp/sdk (TypeScript)Not in this toolNot in this toolNot in this tool
Beyond MCPNoAgent skillsPackage and behavioural code analysis, malware lookupsAgent skills

Sources: snyk/agent-scan, cisco-ai-defense/mcp-scanner, fr0gger/proximity, protyoya/hecate-public.

The real trade-off: patterns or models

Pattern-based detection (Hecate, Cisco’s YARA engine, Proximity without an LLM) is fast, free to run, reproducible and private: the same input always gives the same result, and nothing leaves your machine. It is also literal. An injection worded in a way no rule anticipates will pass.

Model-based detection (an LLM, or a hosted API such as Snyk’s) can recognise intent in text it has never seen. The costs are that your tool definitions go to a model or service, results can vary between runs, and each scan has a price or needs a key.

Neither approach makes an agent safe on its own, because the most damaging attacks (rug pulls after review, and prompt injection through content at runtime) are not visible in a one-off scan at all.

Which one to use

  • Every pull request, in CI: a deterministic scanner that fails the build and never needs network access or keys. Hecate is built for this: exit codes, SARIF annotations and a committed lockfile for rug-pull checks.
  • Before adopting a new server: add a model-based scan for a second opinion on tool text, if your policy allows sending definitions to a model or service.
  • Reviewing a server’s code or package: Cisco’s behavioural and package analysis goes beyond tool metadata.
  • While the agent runs: a runtime guard (Hecate’s SDK for TypeScript agents) to hide changed tools, gate command execution and break the lethal trifecta with approvals.

Layering tools is normal. The combination that matters most is a scan before connection, pinned definitions checked continuously, and least privilege for each agent.