Powered by OWASP MCP Top 10

Is your MCP
setup safe?

Find out in 60 seconds. ShieldMCP scans your MCP configuration and flags permission risks, exposed secrets, and supply chain threats — before an attacker does.

82%of MCP serversprone topath traversal

Source: Endor Labs analysis of 2,614 MCP implementations (2025)

Don't know where your config is? View guide

How it works

Three steps to a safer MCP setup.

01

Upload config

Drop your file or paste JSON. Supports claude_desktop_config.json, .cursor/mcp.json, and more.

02

Instant scan

60-second check across all OWASP MCP Top 10 categories. No account needed.

03

Fix issues

Get exact config fixes in plain English. Unlock the full report for copy-paste JSON examples.

What we check

Full coverage of the OWASP MCP Top 10.

ID
Category
Description
MCP01
Token Mismanagement & Secret Exposure
Secrets & API keys in plaintext
MCP02
Privilege Escalation via Scope Creep
Over-broad filesystem, database & API scope
MCP03
Tool Poisoning
Malicious or unverified MCP packages with hidden directives
MCP04
Software Supply Chain Attacks & Dependency Tampering
Unverified packages, unpinned versions & dependency confusion
MCP05
Command Injection & Execution
Shell execution & dangerous commands
MCP06
Intent Flow Subversion
External content ingestion as indirect injection vector
MCP07
Insufficient Authentication & Authorization
Insecure connections, missing auth & public binds
MCP08
Lack of Audit and Telemetry
Missing logs for agent actions
MCP09
Shadow MCP Servers
Hidden or unverified server endpoints
MCP10
Context Injection & Over-sharing
PII over-sharing & source+sink exfiltration paths

Simple pricing

Start free. Unlock details when you need them.

Free

$0

Always free

  • Risk score
  • Category flags
  • Issue titles
  • Server ratings
Run Free Scan
MOST POPULAR

Full Report

$49one-time

Per scan report

  • Everything free +
  • Full fix steps
  • Config examples
  • Priority order
  • Shareable PDF

Pro

Coming soon
$19/month

For teams

  • Everything $49 +
  • API access (CI/CD)
  • Auto-rescan alerts
  • Scan history
  • Team configs (5)
  • Slack alerts

“82% of MCP servers are prone to path traversal — and 67% to code injection”

— Endor Labs, analysis of 2,614 MCP implementations (2025)

Recent MCP Security Incidents

Asana MCP flaw~1,000 orgs affected· June 2025
postmark-mcp malicious server~300 orgs· Sept 2025
82% of 2,614 MCP servers vulnerable to path traversalEndor Labs· 2025