16 scanners.
One verdict.
Every MCP server runs through the same gauntlet. Each engine produces a sub-score; the weighted sum becomes the trust light. No hidden weights, no "AI vibes" — just published rules.
All 16, in the open.
Filter by category. Each card shows what it tests and where to read its rule definitions.
Static, pipeline, and bytecode analysis for AI skill code detecting unsafe patterns and policy violations.
Scans Agent-to-Agent protocol implementations for security issues using YARA and heuristics.
AI Bill of Materials generator mapping models, agents, tools, and workflows in a codebase.
Custom YARA rules detecting MCP-specific threat patterns, suspicious agent behaviors, and known-bad signatures.
Fast static analysis with custom MCP security rules for command injection, path traversal, and more.
Python AST-based security linter with 47+ checks for SQL injection, hardcoded passwords, and unsafe deserialization.
Detects secrets in code using entropy analysis and pattern matching.
Detects hardcoded secrets, API keys, tokens, and passwords in source code and git history.
IaC scanner for Terraform, CloudFormation, Kubernetes, Dockerfile, and CI/CD pipeline misconfigurations.
SBOM generator producing CycloneDX inventory of all software components in a repository.
Vulnerability scanner matching dependencies and OS packages against known CVE databases.
License compliance scanner detecting declarations and flagging copyleft or restrictive licenses.
Comprehensive vulnerability scanner for containers, dependencies, IaC, and supply chain risks.
Multi-ecosystem vulnerability scanner checking Python, npm, Go, Rust, and Java deps against the OSV database.
Python dependency vulnerability scanner checking against the Python Advisory Database.
Prompt injection detector scanning MCP tool descriptions for patterns that manipulate LLM behavior.
Want your scanner listed?
MCPAmpel aggregates 16+ security engines. If you maintain a scanner for MCP servers, AI tools, or supply chain security, we'd like to hear from you.
Email usFrom 16 sub-scores to one number.
Every engine returns a 0–10 sub-score with a confidence band. We combine them with fixed published weights — no learned model, no per-server tuning. The weighted mean is your trust light. A single critical CVE can floor the score regardless of weight; that's the only nonlinearity.