Your MCP Server Is Probably Overprivileged - Here's a Scanner For It

TL;DR AI
2 min readKey summary
A new MCP security scanner, @hailbytes/mcp-security-scanner, checks both configs and live endpoints for common risks.
It flags overprivileged filesystem access, missing authentication, prompt-injection-prone tool descriptions, and insecure defaults.
The tool supports static and dynamic analysis, and can export SARIF for GitHub Code Scanning and CI pipelines.
Its goal is to catch MCP server misconfigurations before they reach production or get exposed to model prompts.
