Skip to content

Security scan results for mcp-gateway β€” MCPSafe AIVSS 78/100 (Grade C)Β #64

@mcpsafe-gh

Description

@mcpsafe-gh

Hi team πŸ‘‹

I ran a free deep security scan of microsoft/mcp-gateway using MCPSafe β€” a purpose-built scanner for MCP servers using a 5-LLM consensus panel to detect prompt injection risks, over-scoped tool schemas, supply chain issues, and more.

Results: 78/100 Β· Grade C

Severity Count
πŸ”΄ Critical 0
🟠 High 2
🟑 Medium 12
🟒 Low 0

Summary: 2 high + 12 medium findings β€” use with caution for a gateway handling MCP traffic and routing across services

πŸ“‹ Full report with findings and evidence: https://mcpsafe.io/registry/github/microsoft/mcp-gateway


Add a security badge to your README

[![MCPSafe](https://api.mcpsafe.io/badge/github/microsoft/mcp-gateway.svg)](https://mcpsafe.io/registry/github/microsoft/mcp-gateway)

This badge auto-updates whenever a new scan runs β€” great for showing users and enterprise customers your security posture at a glance.


Feel free to close this if you're already tracking these findings. Happy to answer any questions about specific findings.

β€” Truong BUI Β· mcpsafe.io

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions