MCP Scanner
What the Scanner Does
The MCP Scanner performs automated behavioral analysis of MCP servers across 6 dimensions. It connects to each server, exercises its tools, monitors its behavior, and catalogs observations. The result is a safety profile your agent can check before connecting to an unfamiliar MCP server.
This is the only systematic safety assessment of the MCP ecosystem. GitHub stars and README promises don't tell you what a server actually does — the scanner does.
6 Scan Dimensions
Coverage
75+ MCP servers scanned across the public ecosystem. 523+ behavioral observations catalogued. 6 critical findings identified and reported. These counts were recorded April 29, 2026 and have not been re-measured since; when they are, the date moves with them. The scanner runs continuously — new servers are added as they appear in registries.
API Usage
Two doors. Keyless: submit a quick scan, then poll it by scan_id. Keyed (the full scanner, with cadence and callbacks): POST /v1/scanner/submit then GET /v1/scanner/status/{scan_id}. The same check has a browser landing at api.bluefoxedge.ai/verify-mcp.
curl -sS -X POST https://api.bluefoxedge.ai/v1/verify/quick \
-H "Content-Type: application/json" \
-d '{"target": "@modelcontextprotocol/server-filesystem"}'
curl -sS https://api.bluefoxedge.ai/v1/verify/quick/<scan_id>The submit answers with a scan_id, a status and a poll_url; the poll carries the result once the scan completes. Field names below are the served OpenAPI's for GET /v1/verify/quick/{scan_id} — a scan probes the server you name, so this page shows the shape and leaves the run to you:
{
"data": {
"scan_id": "…",
"entity_id": "…",
"status": "…",
"modules_completed": [],
"modules_pending": [],
"findings": [],
"summary": {},
"scanned_at": "…",
"duration_ms": 0,
"cached": false
},
"meta": { "request_id": "…", "timestamp": "…" }
}Interpreting Results
The poll response carries status first, then summary and findings once the scan completes; the six dimensions above are what the scanner reports on.
Use the scanner before connecting your agent to an unfamiliar MCP server. Call the /v1/verify/quick endpoint shown above from your agent's workflow for automated pre-connection safety checks.