Is your MCP
setup safe?
Find out in 60 seconds. ShieldMCP scans your MCP configuration and flags permission risks, exposed secrets, and supply chain threats — before an attacker does.
Source: Endor Labs analysis of 2,614 MCP implementations (2025)
Drop your MCP config file here
or click to browse
Don't know where your config is? View guide
How it works
Three steps to a safer MCP setup.
Upload config
Drop your file or paste JSON. Supports claude_desktop_config.json, .cursor/mcp.json, and more.
Instant scan
60-second check across all OWASP MCP Top 10 categories. No account needed.
Fix issues
Get exact config fixes in plain English. Unlock the full report for copy-paste JSON examples.
What we check
Full coverage of the OWASP MCP Top 10.
Simple pricing
Start free. Unlock details when you need them.
Full Report
Per scan report
- Everything free +
- Full fix steps
- Config examples
- Priority order
- Shareable PDF
Pro
Coming soonFor teams
- Everything $49 +
- API access (CI/CD)
- Auto-rescan alerts
- Scan history
- Team configs (5)
- Slack alerts
“82% of MCP servers are prone to path traversal — and 67% to code injection”
— Endor Labs, analysis of 2,614 MCP implementations (2025)
Recent MCP Security Incidents