🤖 Curated AI OSINT resources — Google dorks, Shodan queries, GitHub dorks, and techniques to discover exposed LLM endpoints, leaked AI API keys, misconfigured vector databases, and unprotected AI agents
-
Updated
Jun 19, 2026
🤖 Curated AI OSINT resources — Google dorks, Shodan queries, GitHub dorks, and techniques to discover exposed LLM endpoints, leaked AI API keys, misconfigured vector databases, and unprotected AI agents
High-performance zero-dependency static analysis tool enforcing NASA Power of Ten rules across 20 programming languages, plus AI agent skill, MCP server config, prompt template, and LLM model security auditing.
Open-source CLI scanner for agentic AI components such as skills, MCP servers, system prompts
Active red-teaming for MCP servers. Source analysis + live exploitation + auto-fix. Claude Code plugin.
Scan any MCP server for prompt injection, tool poisoning, and leaked secrets. One command, no key. SARIF + GitHub Action.
Python security scanner for Model Context Protocol (MCP) servers — find prompt injection, over-broad permissions, weak input validation, and credential leaks before your AI agent does.
Security scanner for MCP server configurations — npm audit for the AI agent era. npx mcp-audit-cli
Free MCP security checks, examples and developer tools for understanding MCP configuration, tool exposure, change and runtime trust posture.
Add a description, image, and links to the mcp-scanner topic page so that developers can more easily learn about it.
To associate your repository with the mcp-scanner topic, visit your repo's landing page and select "manage topics."