MCP Configuration Security Scanner Fabrica-STAR Released
Key point
Fabrica-STAR, an open-source tool that checks security vulnerabilities in Claude Desktop and MCP servers, has been released.
Details
Fabrica-STAR, which automatically detects security vulnerabilities in MCP (Model Context Protocol) servers used by Claude Desktop, Claude Code, Cursor, and others, has been released.
Following recent reports of supply chain attacks via MCP servers, the tool focuses on checking the following security items:
- Detection of hardcoded API keys and tokens
- Checking for unpinned packages (such as use of the latest tag)
- Cross-referencing against a list of known malicious servers
- Checking for typosquatting package names
- Detecting excessively permissive file system access and plaintext HTTP communication
Users can run an immediate scan via the npx fabrica-star scan command without any separate installation or account creation, and testing is also possible directly in a web browser.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.