This product was not featured by Product Hunt yet. It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).
Product upvotes vs the next 3
Waiting for data. Loading
Product comments vs the next 3
Waiting for data. Loading
Product upvote speed vs the next 3
Waiting for data. Loading
Product upvotes and comments
Waiting for data. Loading
Product vs the next 3
Loading
MCPScan
Discover & audit shadow Model Context Protocol servers
MCPScan is an offline, zero-telemetry security scanner that discovers and audits Model Context Protocol (MCP) servers across your private network and local AI tools (Claude Desktop, Cursor, Antigravity, VS Code). It detects open HTTP endpoints and dormant stdio servers, audits authentication enforcement with a non-destructive single probe, and automatically sanitizes embedded CLI secrets. Single binary in Go with zero dependencies.
Hey Product Hunt!
As the Model Context Protocol (MCP) rapidly becomes the standard for connecting LLMs to databases, terminals, and internal APIs, a silent security challenge has emerged: **Shadow MCP Servers**.
Developers and teams are configuring MCP servers across multiple AI tools (Claude Desktop, Cursor, VS Code, Gemini IDE) or exposing local HTTP servers on standard ports often completely unauthenticated, with access to internal company data and local shells.
We built MCPScan to give developers and SecOps teams complete visibility into their MCP attack surface.
### What MCPScan does:
- **Dual-Transport Discovery:** Scans private CIDR networks for HTTP MCP servers and inspects local AI tool configurations (Claude Desktop, Cursor, Antigravity, VS Code).
- **3-Layer MCP Verification:** Differentiates real MCP servers from generic JSON-RPC gateways and Ethereum nodes to prevent false positives.
- **Single-Probe Auth Auditing:** Sends exactly 1 unauthenticated request per server to check whether tools/resources are exposed without authorization (no brute forcing, zero state changes).
- **Active vs. Dormant Process Matching:** Cross-references local configs with running OS processes to find active servers and dormant shadow configurations.
- **Privacy & Secret Security:** 100% offline, zero telemetry, zero storage of `env` variable contents, and automatic masking of sensitive API keys/tokens in CLI arguments.
It's compiled as a single zero-CGO binary for Windows, macOS, and Linux with embedded SQLite reporting.
Would love to hear your thoughts, feedback, and any other AI tools you'd like us to support next!
About MCPScan on Product Hunt
“Discover & audit shadow Model Context Protocol servers”
MCPScan was submitted on Product Hunt and earned 2 upvotes and 1 comments, placing #100 on the daily leaderboard. MCPScan is an offline, zero-telemetry security scanner that discovers and audits Model Context Protocol (MCP) servers across your private network and local AI tools (Claude Desktop, Cursor, Antigravity, VS Code). It detects open HTTP endpoints and dormant stdio servers, audits authentication enforcement with a non-destructive single probe, and automatically sanitizes embedded CLI secrets. Single binary in Go with zero dependencies.
On the analytics side, MCPScan competes within Developer Tools, Artificial Intelligence and GitHub — topics that collectively have 1M followers on Product Hunt. The dashboard above tracks how MCPScan performed against the three products that launched closest to it on the same day.
Who hunted MCPScan?
MCPScan was hunted by Kuldeep Poonia. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
For a complete overview of MCPScan including community comment highlights and product details, visit the product overview.