Skip to content

Releases: kuldeep-poonia/mcpscan

v1.2.0: Advanced Upgrade Suite

Choose a tag to compare

@kuldeep-poonia kuldeep-poonia released this 17 Aug 11:43

MCPScan v1.2.0 — Advanced Security Upgrade

MCPScan v1.2.0 introduces the Advanced Upgrade Suite — adding three passive, deterministic detection capabilities grounded in empirical MCP security research without external LLM dependencies, composite scoring formulas, or destructive changes.


What's New in v1.2.0

1. Transport Security (HTTPS Compliance Check)

  • Identifies whether HTTP endpoints operate over unencrypted plaintext HTTP or encrypted HTTPS (TLS presence detection without certificate authority trust assumptions).
  • Surfaces wire-interception exposure independently of authentication status.
  • Includes empirical error-fallback probing and worst-case detection latency disclosures.

2. Parameter-Shape Danger Detection

  • Passively inspects tool parameter schemas (inputSchema) during Layer 3 verification.
  • Flags unconstrained string parameters matching high-risk system terms (command, path, sql, script, exec, eval, shell), closing the evasion gap for innocuously-named tools (run_task).
  • Features tokenized matching, safe-prefix deny-listing (zip_code, status_code, etc.), and enum-exemption to eliminate false positives.

3. Tool-Definition & Config Integrity Check ("Rug Pull" Detection)

  • Computes deterministic, canonical SHA-256 digests over tool definitions (HTTP) and execution parameters (Stdio) to detect silent mutations over time.
  • Port-Reuse Disambiguation: Correlates serverInfo.name to distinguish genuine tool mutations (modified) from different software starting on the same port (replaced).
  • Cross-scan integrity tracking across sequential runs (new → unchanged → modified → replaced).

Verification & Compatibility

  • Backward Compatibility: Seamless automatic SQLite schema migration for all pre-existing .db databases.
  • 100% Test Suite Pass: Verified across all network, detector, storage, and report subsystems.
  • Zero Additional Network Calls: Parameter heuristics and tool hashing operate in-memory on data already captured during Layer 3 verification.

Checksums (SHA-256)

4b4dce45daad09fcc9c63e3e6cc15922e20f3a839cd2a94884b32f1999731e20  mcpscan-darwin-amd64
fbddf2ae8aae6712961683df5acfb0e53b56ec0398a34a91f80052f168286b95  mcpscan-darwin-arm64
83b049e414008d57da804d7318f019cdc922e825a9e8cf8464e48c46d0dc523c  mcpscan-linux-amd64
c581639411c8473199ee8ada049b070440d61b17fd569958bacfabad494cab59  mcpscan-windows-amd64.exe

v1.1.1 — Patch: Storage Timestamps & Transport Mapping

Choose a tag to compare

@kuldeep-poonia kuldeep-poonia released this 16 Aug 03:46

MCPScan v1.1.1 Release Notes

Fixes & Improvements

  • Storage Readback Timestamps: Fixed SQLite timestamp deserialization in GetLastScan and GetStdioDiscoveredServers so started_at, ended_at, and detected_at retain their true RFC3339 timestamps when queried via mcpscan report.
  • Target Range Resolution: Ensured target_range is populated with 127.0.0.1 on local loopback scans.
  • HTTP Transport Type: Populated transport: "http" explicitly across all network-discovered server records.

v1.1.0 — Local Stdio Transport MCP Server Discovery

Choose a tag to compare

@kuldeep-poonia kuldeep-poonia released this 14 Aug 06:07

MCPScan v1.1.0 Release Notes

What's New in v1.1.0

  • Local Stdio Transport Detection (--include-stdio): Opt-in discovery of local Model Context Protocol servers configured across major AI developer tools:
    • Claude Desktop
    • Cursor
    • Antigravity (Gemini IDE)
    • VS Code
  • 3-Layer Stdio Verification Pipeline:
    • Layer 1: JSON syntax parsing bounded by a 5MB read cap.
    • Layer 2: Schema structural validation (mcpServers definitions; HTTP entries filtered to prevent double-counting).
    • Layer 3: Non-elevated OS process cross-referencing (Windows CIM Win32_Process, Linux /proc, macOS ps) to confirm actively running servers.
  • Privacy Guarantees & Two-Layer Secret Masking:
    • Zero env Storage: Environment variable keys and values inside env blocks are never stored or displayed (only a boolean flag is set).
    • Command/Arg Sanitization: Sensitive CLI flags (--api-key, token=), HTTP headers (Header: Value), and high-entropy secret tokens are partially masked (sk-...789), while legitimate filesystem paths are preserved.
  • Dual-Transport Reporting:
    • ASCII tables with dedicated STDIO-TRANSPORT MCP SERVERS section.
    • Clean, un-nested JSON export with separated discovered_servers (HTTP) and stdio_servers (Stdio).
  • SQLite Persistence Hardening:
    • stdio_discovered_servers table with ON DELETE CASCADE foreign key integrity.
    • File permission restrictions (0600 on Unix, Windows ACL inheritance stripping).

Checksums (SHA-256)

  • mcpscan-windows-amd64.exe: cadebf9fd04b4cf384007666584119d8717525e2f4a1c876f7a15f3afcdbc6d6
  • mcpscan-linux-amd64: 8b269be568676c3bb9701df5e169d5714e8d0a74e7cd4c16212bddfc4ad8aeb6
  • mcpscan-darwin-amd64: 5f64ef5c98fbd5c85ff453e1553baf27ddee0c8354ccc6fc43a402f82caa33b3
  • mcpscan-darwin-arm64: 03c0ccdcbcd6a9504c3aad01f9df9f20df95bf30c95e1b65b4ea61b40bd309a4

v1.0.1 — Fix Handshake-Protected MCP Server Detection

Choose a tag to compare

@kuldeep-poonia kuldeep-poonia released this 13 Aug 11:03

Fixes architectural gap: HTTP 401/403 responses during initialize handshake with WWW-Authenticate header or JSON payload are now classified as unverifiable_protected rather than dropped to none.

v1.0.0 — MCPScan Initial Release

Choose a tag to compare

@kuldeep-poonia kuldeep-poonia released this 13 Aug 05:18

First production release of MCPScan — Local-only Shadow MCP Server Discovery & Auth Audit Tool.