I built a deterministic scanner that catches command injection, prompt-injection markers in tool descriptions, over-broad/destructive tools, and committed secrets in MCP servers before you connect them. It continuously scans the entire official MCP registry and makes results available at https:/...
Source: [Hacker News](https://index.canopii.dev/cli)