Agent security & threat detection
Cisco MCP Scanner
Apache-2.0 Python tool from Cisco's AI Defense group that scans MCP servers, their tools, prompts and resources plus server source code, combining YARA rules, LLM-based analysis and Cisco's hosted inspection API, and audits dependencies and bundled binaries. Full detection depth depends on optional third-party services.
open_source · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Agent security & threat detection · Evaluation & testing
Useful conversation with: AppSec engineer, CISO, AI platform lead.
Ask for a demonstration
Show me a scan of an untrusted MCP server package that flags a docstring-versus-implementation mismatch, and which findings required the Cisco AI Defense API.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
The repository states MCP Scanner combines the Cisco AI Defense inspect API, YARA rules and LLM-based analysis to detect malicious MCP tools and can scan tools, prompts, resources and server instructions.
Limit: Detection efficacy is not benchmarked publicly; the inspect API is a Cisco-hosted commercial dependency.
Source s1
Documented by provider
The repository states it scans MCP server source code for behavioural threats, detects mismatches between docstring claims and implementation with cross-file dataflow tracking, audits Python dependencies via pip-audit for CVE/PYSEC/GHSA issues, and hash-checks bundled binaries via VirusTotal.
Limit: VirusTotal and pip-audit are external services; offline coverage and false-positive rates are not documented.
Source s1
Documented by provider
The GitHub repository metadata records an Apache-2.0 license, a non-archived state and commits in September 2026.
Limit: Repository activity does not establish maintenance commitments or release cadence.
Source s2
Limitations to discuss
- Best results depend on Cisco's commercial inspect API
- No published detection benchmarks
Sources
- cisco-ai-defense/mcp-scanner · Cisco / GitHub · official repository
Access date reported by researcher: 2026-09-06 - GitHub REST API repository record · GitHub · official repository
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction