Release Notes
Added
- Multi-stage MCP server discovery pipeline (port scan, HTTP heuristic, MCP handshake, validation, enumeration)
- Confidence-scored results (Confirmed/Likely/Unlikely) with evidence tracking
- Passive security detections: DNS rebinding (MCP-001), missing auth (MCP-002), insecure transport (MCP-003), weak session IDs (MCP-004), dangerous tools (MCP-005), prompt injection (MCP-006)
- Active behavioral probing with three tiers: safe metadata-only (Tier 1), LOW-risk tool calls (Tier 2), MEDIUM-risk tool calls (Tier 3)
- Active detections: resource injection (MCP-007), schema poisoning (MCP-008), tool squatting (MCP-009), rug-pull (MCP-010), response injection (MCP-011), denial-of-wallet (MCP-012), exfiltration chains (MCP-013), cross-server manipulation (MCP-014)
- Tool integrity pinning with SHA-256 hashes (
--pin / --verify, MCP-015)
- Streamable HTTP and legacy SSE transport support
- IPv4/IPv6 and CIDR range scanning
- Concurrent scanning with configurable threads and rate limiting
- Graceful shutdown with partial result output on SIGINT
- Multiple output formats: normal table, wide (grep-friendly), JSON
--dry-run mode for previewing active probe plans
- Safety controls: CRITICAL/HIGH tools never called, per-tool/per-server call limits, timeouts
Install mcpmap 0.1.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/canack/mcpmap/releases/download/v0.1.0/mcpmap-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/canack/mcpmap/releases/download/v0.1.0/mcpmap-installer.ps1 | iex"
Install prebuilt binaries via Homebrew
brew install canack/tap/mcpmap
Download mcpmap 0.1.0