Cisco mcp-scanner repo
An MCP server security scanner from Cisco AI Defense that checks tools, prompts, resources, and server instructions for prompt injection, tool poisoning, and vulnerable dependencies, using API, YARA, and LLM based analysis engines.
What it does for you: Points at any MCP server Axion connects to and flags prompt injection, tool poisoning, and dependency vulnerabilities before YY trusts that server with real tool calls. It is a named, credible vendor (Cisco) entering this space three days after an industry report scanned 268,210 agent tools across 25,264 MCP servers and found some vulnerability in 73 percent of them, the same finding behind three of yesterday's top picks.
In practice: Solid, actively maintained vendor tool with real engineering behind it, though this particular update is routine hygiene rather than a breakthrough.
For: Both runtimes. Runs as a standalone CLI or REST API against any MCP server, so it can audit either Axion's or a future Hermes runtime's MCP connections.
Verdict: test first. A credible vendor's MCP security scanner is worth running against Axion's existing MCP connections, even though this specific update is just a dependency CVE patch.
Build #1 Cisco mcp-scanner: use the ai-implementation-build-intake skill to build this safely. Source: https://github.com/cisco-ai-defense/mcp-scanner. Save canonical skill/agent under AXION\Skills and AXION\Agents.
Source · Version 4.8.6 released October 7, 2026, bumping the litellm dependency to 1.93.2 to fix CVE-2026-84377. Repo has 1.1k stars and is Apache 2.0 licensed.