Markets
An MCP Security Auditor Went Up on Apify at $0.25 Per Server, Scanning Five CWE Classes Without Executing Code
Neon Innovation Lab posted an MCP Security & Vulnerability Auditor to Show HN on 2026-09-04, priced pay-per-event at $0.25 per server audited. It uses pure static analysis on the syntax tree and configs, deliberately avoiding execution because running untrusted MCP code is itself an RCE path, and it detects command injection (CWE-78), path traversal (CWE-22), secret exposure (CWE-798), unauthenticated transport (CWE-306) and tool poisoning (CWE-1384), emitting a 0-100 trust score with file and line-level findings. Adoption is 2 total users, so this is an early signal not a market, and independent research puts YARA-based MCP scanner false-positive rates around 78%.
↳ Follow the thread