Static security scanner for MCP servers, AI agent skills, and plugins. Detects 68+ malicious patterns across 4 severity levels.
The 'scan' tool has a name that does not clearly describe what it scans for. The description is adequate (107 chars, within baseline 34-392 range) but the input parameter lacks a description entirely. The tool has an input schema with types, but critically lacks any output schema documentation. The server provides no error handling guidance, no parameter constraints (e.g., max content length), and no recovery paths for edge cases. Tool name 'scan' is generic and does not follow verb_noun convention (should be 'scan_code' or 'scan_for_malicious_patterns'). This is a single-tool server with structural definition gaps that would significantly hinder LLM tool selection and chaining.
Scans code content for malicious patterns and security threats. Returns structured findings with severity levels, pattern IDs, matched text, line numbers, and risk scoring.
Tool name 'scan' is too generic and does not follow verb_noun naming convention. Does not convey intent, could mean scan files, scan code, scan security, etc. Should be 'scan_code_for_threats' or 'analyze_code_for_malicious_patterns'.
Input parameter 'content' has no description. LLMs cannot determine if this expects raw source code, file paths, URLs, or compiled binaries.
No output schema documented. Tool description mentions 'structured findings with severity levels, pattern IDs, matched text, line numbers, and risk scoring' but the actual response structure is not formally defined. LLMs cannot plan downstream operations without knowing return fields.
No input validation or constraints. Parameter 'content' is unbounded, no max length specified. An LLM could pass 100MB+ of code, causing OOM or timeout. Rubric requires 'Specify minimum and maximum for numeric parameters' and format constraints.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 44 | 2026-07-28+ | v2 |
No error handling guidance. Tool description does not explain what happens if content is too large, malformed, empty, or in an unsupported language. No recovery paths documented per 'error-classification' pattern.
STDIO-only transport means the server is not remotely accessible and cannot integrate with hosted MCP clients. Requires local child process spawning only.