Home / Problems / Audit MCP servers before connecting them

Workflow problem

Audit MCP servers before connecting them

An MCP server may access files, credentials or external services, and its tool descriptions can influence an agent’s behavior.

The problem

An MCP server may access files, credentials or external services, and its tool descriptions can influence an agent’s behavior.

Native approach

Review the server source, requested permissions and configuration before adding it. Limit credentials and filesystem scope, then test it in a restricted environment.

Official Claude Code documentation ↗

Tools to consider

The mcp-scanner catalog entry documents Cursor support, not Claude Code integration; use it as a separate audit tool.

FAQ

Does a security scan prove a server is safe?

No. It provides findings for review and cannot prove absence of risk.

Should I share production credentials with an unreviewed server?

No. Grant only the access required after review.