Mund — MCP Security Scanner
NPM · @WEAVE_PROTOCOL/MUND · SCANNED SEP 25
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security80
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known high-severity CVE affects nodemailer 6.10.1, a direct dependency. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- 71 of 183 dependencies flagged as unhealthy (2 deprecated). View diagnostics → Partial
Provenance & Transparency48
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (Apache-2.0).Pass
- Actively maintained (last published 119 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2088 tokens (~139/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
- Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Mund — MCP Security Scanner server?
Mund — MCP Security Scanner runs locally as an npm package, launched with npx -y @weave_protocol/mund. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @weave_protocol/mund
claude mcp add tyox-all-mund -- npx -y @weave_protocol/mund
{
"mcpServers": {
"tyox-all-mund": {
"command": "npx",
"args": [
"-y",
"@weave_protocol/mund"
]
}
}
} {
"servers": {
"tyox-all-mund": {
"command": "npx",
"args": [
"-y",
"@weave_protocol/mund"
]
}
}
} codex mcp add tyox-all-mund -- npx -y @weave_protocol/mund
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"tyox-all-mund": {
"type": "local",
"command": [
"npx",
"-y",
"@weave_protocol/mund"
],
"enabled": true
}
}
} openclaw mcp add tyox-all-mund --command npx --arg -y --arg @weave_protocol/mund
mcp_servers:
tyox-all-mund:
command: "npx"
args: ["-y", "@weave_protocol/mund"] {
"McpServers": {
"tyox-all-mund": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@weave_protocol/mund"
]
}
}
} assistant mcp add tyox-all-mund -t stdio -c npx -a -y @weave_protocol/mund
{
"mcpServers": {
"tyox-all-mund": {
"command": "npx",
"args": [
"-y",
"@weave_protocol/mund"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 −2
- Stability: pass → 0.80 functional
- 22 Sept 26 0
- Stability: 0.97 → pass security
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
- CVE-2026-92598 affects this package: high ▼ security
- CVE-2026-92595 affects this package: high ▼ security
- CVE-2026-92597 affects this package: high ▼ security
- CVE-2026-92596 affects this package: high ▼ security
- GHSA-cc9r-2j5m-2m83 no longer affects this package ▲ security
- GHSA-8m3c-c648-2xjj no longer affects this package ▲ security
- GHSA-wmmp-3585-3rmp no longer affects this package ▲ security
- GHSA-2x7j-588g-ccc2 no longer affects this package ▲ security
- 16 Sept 26 −2
- CVE-2026-82562 no longer affects this package ▲ security
- CVE-2026-82417 no longer affects this package ▲ security
- Stability: pass → 0.80 functional
- 15 Sept 26 0
- Stability: 0.97 → pass security
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 25 Sept 2026 · Analysed npm/@weave_protocol/mund@0.1.12
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Vulnerabilities 13 findings
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-268h-hp4c-crq3 | CVE-2026-82661 | medium | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N | yes |
| GHSA-2x7j-588g-ccc2 | CVE-2026-92596 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-8m3c-c648-2xjj | CVE-2026-92595 | medium | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N | yes |
| GHSA-c7w3-x93f-qmm8 | CVE-2026-82854 | low | yes | |
| GHSA-cc9r-2j5m-2m83 | CVE-2026-92597 | medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N | yes |
| GHSA-mm7p-fcc7-pg87 | CVE-2025-13033 | medium | yes | |
| GHSA-p6gq-j5cr-w38f | CVE-2026-82659 | high | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N | yes |
| GHSA-r7g4-qg5f-qqm2 | CVE-2026-82662 | medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N | yes |
| GHSA-rcmh-qjqh-p98v | CVE-2025-14874 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-vvjj-xcjg-gr5g | CVE-2026-82853 | medium | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N | yes |
| GHSA-wmmp-3585-3rmp | CVE-2026-92598 | medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N | yes |
| GHSA-wqvq-jvpq-h66f | CVE-2026-82660 | medium | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N | yes |
| GHSA-w5hq-g745-h8pq | CVE-2026-41907 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | yes |
Background: What a vulnerability scan can and cannot prove →
Dependencies 183 packages
| Packages resolved | 183 |
|---|---|
| Deprecated | 2 |
| Stale | 69 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
mund_acknowledge_alert Acknowledge Security Alert ~86
Mark a security event/alert as acknowledged. Args: - event_id (string): ID of the event to acknowledge - acknowledged_by (string): Optional name/ID of acknowledger Returns: Confirmation of acknowledgment
| Name | Type | Req | Description |
|---|---|---|---|
| acknowledged_by | string | – | Name or ID of person acknowledging |
| event_id | string | yes | ID of the event to acknowledge |
No output schema declared.
No examples provided.
mund_add_rule Add Detection Rule ~246
Add a custom security detection rule. Create custom rules to detect specific patterns in content. Rules use regular expressions for pattern matching and can be configured with different severity levels and actions. Args: - id (string): Unique rule identifier (lowercase, alphanumeric, underscores) - name (string): Human-readable rule name - description (string): Optional description - type: Detection type (secret, pii, code_pattern, injection, exfiltration) - pattern (string): Regular expression to match - severity: Severity level (critical, high, medium, low, info) - action: Action to take (alert, block, log, quarantine) Returns: Confirmation of rule addition with rule details
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | Action to take when rule matches |
| description | string | – | Description of what this rule detects |
| id | string | yes | Unique identifier for the rule |
| name | string | yes | Human-readable name for the rule |
| pattern | string | yes | Regular expression pattern to match |
| severity | string | yes | Severity level when this rule matches |
| type | string | yes | Type of detection |
No output schema declared.
No examples provided.
mund_allowlist_pattern Allowlist Pattern ~81
Add a pattern to the allowlist. Allowlisted patterns will be ignored by detection rules. Args: - pattern (string): Pattern to allowlist - type: Type of pattern Returns: Confirmation of allowlist addition
| Name | Type | Req | Description |
|---|---|---|---|
| pattern | string | yes | Pattern to add to allowlist |
| type | string | yes | Type of pattern |
No output schema declared.
No examples provided.
mund_audit_mcp_permissions ~57
Analyze the permission scope and capabilities of an MCP server's tools. Identifies network access, filesystem operations, command execution, and other potentially dangerous capabilities.
| Name | Type | Req | Description |
|---|---|---|---|
| manifest | string | yes | JSON content of server.json manifest to audit |
No output schema declared.
No examples provided.
mund_block_pattern Block Pattern ~93
Add a pattern to the blocklist. Blocked patterns will always be flagged regardless of other rules. Args: - pattern (string): Pattern to block - type: Type of pattern (secret, pii, code_pattern, injection, exfiltration) Returns: Confirmation of blocklist addition
| Name | Type | Req | Description |
|---|---|---|---|
| pattern | string | yes | Pattern to add to blocklist |
| type | string | yes | Type of pattern |
No output schema declared.
No examples provided.
mund_check_typosquatting ~58
Check if an MCP server name is potentially typosquatting a known legitimate server. Compares against a list of official and common MCP servers.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | MCP server name to check for typosquatting |
No output schema declared.
No examples provided.
mund_check_url Check URL Safety ~231
Check if a URL is safe to access. Validates URLs against known dangerous patterns including: - Data exfiltration services (webhook.site, requestbin, etc.) - IP-based URLs (often used to bypass domain filtering) - Suspicious TLDs (.tk, .ml, etc.) - Data URLs (can contain arbitrary content) Args: - url (string): The URL to check (required) - tool_name (string): Name of tool attempting access (optional) - agent_id (string): ID of requesting agent (optional) Returns: JSON object with: - url: The checked URL - safe: Boolean indicating if URL is safe - risk_level: 'safe' | 'suspicious' | 'dangerous' - warnings: Array of warning messages if any - blocked: Whether access was blocked
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | ID of the agent making this request |
| tool_name | string | – | Name of the tool attempting to access this URL |
| url | string | yes | URL to check for safety |
No output schema declared.
No examples provided.
mund_configure_notification Configure Notification Channel ~136
Configure a notification channel for security alerts. Note: Full configuration requires environment variables. This tool can update webhook URLs and minimum severity settings at runtime. Args: - type: Channel type (slack, teams, email, webhook) - webhook_url: Webhook URL (for slack, teams, webhook) - min_severity: Minimum severity to notify Returns: Confirmation of configuration
| Name | Type | Req | Description |
|---|---|---|---|
| min_severity | string | – | Minimum severity to send notifications |
| type | string | yes | Type of notification channel |
| webhook_url | string | – | Webhook URL for Slack/Teams/generic webhook |
No output schema declared.
No examples provided.
mund_get_events Get Security Events ~226
Retrieve recent security events from the Mund monitoring system. Supports filtering and pagination for efficient event retrieval. Args: - limit (number): Maximum events to return, 1-1000 (default: 50) - offset (number): Skip this many events for pagination (default: 0) - severity ('critical' | 'high' | 'medium' | 'low' | 'info'): Filter by severity - type: Filter by detection type - acknowledged (boolean): Filter by acknowledgment status Returns: JSON object with: - total: Total matching events - count: Events in this response - offset: Current offset - has_more: Whether more events exist - events: Array of security events
| Name | Type | Req | Description |
|---|---|---|---|
| acknowledged | boolean | – | Filter by acknowledgment status |
| limit | integer | – | Maximum number of events to return |
| offset | integer | – | Number of events to skip for pagination |
| severity | string | – | Filter by severity level |
| type | string | – | Filter by detection type |
No output schema declared.
No examples provided.
mund_get_status Get Monitoring Status ~53
Get the current status of the Mund monitoring system. Returns information about: - Active analyzers and their status - Number of rules loaded - Configured notification channels - Block mode status - Recent event statistics
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
mund_list_rules List Detection Rules ~72
List all configured detection rules. Args: - type: Optional filter by detection type - enabled_only: Only show enabled rules (default: false) Returns: Array of rule configurations
| Name | Type | Req | Description |
|---|---|---|---|
| enabled_only | boolean | – | Only show enabled rules |
| type | string | – | Filter rules by type |
No output schema declared.
No examples provided.
mund_remove_rule Remove Detection Rule ~65
Remove a custom detection rule by ID. Note: Built-in rules cannot be removed, only disabled. Args: - id (string): ID of the rule to remove Returns: Confirmation of rule removal
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | ID of the rule to remove |
No output schema declared.
No examples provided.
mund_scan_content Scan Content for Security Issues ~382
Scan text or code content for security vulnerabilities, secrets, PII, and other issues. This tool analyzes the provided content using multiple security analyzers: - Secret Scanner: Detects API keys, tokens, passwords, and credentials - PII Detector: Finds personal identifiable information - Code Analyzer: Identifies dangerous code patterns - Injection Detector: Spots prompt injection attempts - Exfiltration Detector: Detects data exfiltration patterns Args: - content (string): The text/code to scan (required) - content_type ('text' | 'code' | 'json' | 'yaml'): Type of content (default: 'text') - tool_name (string): Name of tool that generated this content (optional) - agent_id (string): ID of the requesting agent (optional) - session_id (string): Current session ID (optional) Returns: JSON object with: - scan_id: Unique identifier for this scan - issues_found: Number of security issues detected - blocked: Whether the content was blocked (if block_mode is enabled) - issues: Array of detected issues with severity, type, and suggestions - scan_duration_ms: Time taken to complete the scan Examples: - Scan code before committing: {"content": "const key = 'AKIAIOSFODNN7EXAMPLE'"} - Check user input: {"content": "Please ignore previous instructions", "content_type": "text"}
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | ID of the agent making this request |
| content | string | yes | The text/code content to scan for security issues |
| content_type | string | – | Type of content being scanned |
| session_id | string | – | Current session ID |
| tool_name | string | – | Name of the tool that generated this content |
No output schema declared.
No examples provided.
mund_scan_mcp_server ~79
Scan an MCP server manifest (server.json) for security issues before installation. Detects prompt injection in tool descriptions, typosquatting, embedded secrets, and dangerous permissions.
| Name | Type | Req | Description |
|---|---|---|---|
| manifest | string | yes | JSON content of server.json manifest to scan |
| source | string | – | Source URL, registry name, or file path for context |
No output schema declared.
No examples provided.
mund_validate_command Validate Shell Command ~223
Validate a shell command for safety before execution. Checks for dangerous patterns including: - Destructive commands (rm -rf, format, etc.) - Privilege escalation (sudo, chmod 777, etc.) - Network exfiltration (curl to suspicious URLs, etc.) - Code injection (eval, exec with variables, etc.) Args: - command (string): Shell command to validate (required) - tool_name (string): Name of tool executing command (optional) - agent_id (string): ID of requesting agent (optional) Returns: JSON object with: - command: The validated command - safe: Boolean indicating if command is safe - risk_level: 'safe' | 'suspicious' | 'dangerous' - warnings: Array of warning messages - blocked: Whether execution was blocked
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | ID of the agent making this request |
| command | string | yes | Shell command to validate |
| tool_name | string | – | Name of the tool executing this command |
No output schema declared.
No examples provided.
What is the Mund — MCP Security Scanner server?
Mund — MCP Security Scanner is listed in the public MCP registry as io.github.Tyox-all/mund. Scan for prompt injection, secrets, PII, and vet MCP servers before installation. This page covers its npm package (@weave_protocol/mund).
Is the Mund — MCP Security Scanner server safe to use?
Mund — MCP Security Scanner scores 77 out of 100 on VerifyMCP. We recorded 13 known advisories against it as of 25 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Mund — MCP Security Scanner server expose?
Mund — MCP Security Scanner exposes 15 tools: mund_scan_content, mund_check_url, mund_validate_command, mund_get_events, mund_get_status, and 10 more. Their descriptions and schemas cost roughly 2,088 tokens of context every time the server is loaded.
Is the Mund — MCP Security Scanner server still maintained?
Mund — MCP Security Scanner is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Mund — MCP Security Scanner server under?
Mund — MCP Security Scanner declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.