Other · Local MCP server
Vulnerability Scanner
Triggers GuardBee scans, queries findings, AI-assisted remediation guidance.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.4hmetuyar/vulnerability-scanner- Version
- 0.2.4
- Status
- Active
- Category
- other
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-09-28
- Updated
- 2026-09-28
- Publisher
- 4hmetuyar (GitHub) · 26 servers with pages here
- Repository
- github.com/GuardBee/guardbee-mcp (folder packages/vulnerability-scanner)
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @guardbee/mcp-vulnerability-scanner | 0.2.4 | stdio |
How to connect Vulnerability Scanner
Vulnerability Scanner runs locally from a Node.js package published to the npm registry: @guardbee/mcp-vulnerability-scanner version 0.2.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-vulnerability-scanner@0.2.4.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"vulnerability-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-vulnerability-scanner@0.2.4"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from 4hmetuyar (GitHub)
| Server | Runs |
|---|---|
| Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience. | Local · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | Local · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | Local · stdio |
| Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval. | Local · stdio |
| Secret ScannerScans files for leaked secrets and API keys. | Local · stdio |
| Security ProxyMCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log. | Local · stdio |
| Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence. | Local · stdio |
| Slopsquat ScannerChecks declared npm/PyPI dependencies against real registries to catch slopsquatting. | Local · stdio |
| Tool Poisoning ScannerScans MCP tool definitions for hidden instructions and confused-deputy sinks. | Local · stdio |
| Toxic Flow AuditorFinds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress. | Local · stdio |
| Unbounded Consumption AuditorScans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6) | Local · stdio |
| Vector Store ScannerProbes vector-database endpoints for unauthenticated exposure of embeddings/RAG data. | Local · stdio |
More other servers
| Server | Runs |
|---|---|
| vrsaiMachine-native capabilities with explicit contracts and machine-readable commerce. | Remote · HTTP |
| Vscode Terminal MCPExecute commands in visible VSCode terminal tabs with output capture and session reuse. | Local · stdio |
| Vue HarvestExtract reusable component libraries and design tokens from Vue applications. | Local · stdio |
| vuln-intelHosted CVE + bug-bounty-mechanic MCP: exploitation-first ranking, CVE fact-check, mechanic transfer. | Remote · HTTP |
| W8s Astro MCPNatal charts, transits, history, ingress forecasting, aspects, composite & Davison charts — SQLite. | Local · stdio |
| wa — safe WhatsApp automationSafety-first WhatsApp tools: draft-gated sends, enforced rate limits, append-only audit. | Local · stdio |
| WaAPIMessaging tools for AI agents: send messages, manage chats, groups and channels. | Remote · HTTP |
| WacheteCreate, read and monitor Wachete website-change wachets for a signed-in user. | Remote · HTTP |