MCP-Defender

Desktop app that automatically scans and blocks malicious MCP traffic in AI apps like Cursor, Claude, VS Code and Windsurf.

Stars
254
Last push
2026-06-05
License
AGPL-3.0
Category
Security

Score breakdown — how scoring works

  • Maintenance

    25.5 / 30
    • Pushed within 45 days27 days ago+25.5
  • Adoption

    14 / 25
    • GitHub stars (no package published — stars weighted fully)254+14
  • Documentation

    15 / 25
    • Basic README (1,000+ chars)1775 chars+5
    • Install / setup instructionsyes+6
    • Tools / capabilities documentedno+0
    • Code or client-config exampleyes+4
  • Trust signals

    9 / 20
    • OSS license declaredAGPL-3.0+7
    • First-party vendor implementationno+0
    • DNS-verified registry namespaceno+0
    • Listed in official MCP Registryno+0
    • Owned by an organizationyes+2

Install

From sourcegit clone https://github.com/MCP-Defender/MCP-Defender

No package published to a registry — see the README for setup instructions.

Always review a server's code and required credentials before connecting it to your MCP client. MCP Vetted scores public metadata — it does not audit code for malicious behavior (yet). Methodology →

View on GitHub