Skip to main content
Golf Scanner runs 20 security checks against each MCP server.

Check Applicability by Server Type

Not all checks apply to all server types. The scanner automatically skips checks that don’t apply and marks them as skip in findings.

Checklist IDs

Each finding includes a checklist_id in its metadata field. These IDs identify the exact sub-check that triggered the finding.

ST — Server Type

UC-1 — Command Safety

UC-2 — MCP Registry Verification

UC-3 — GitHub Trust

CD-1 — Credential Detection

SC-1 — Script Location

SC-2 — Script Permissions

BN-1 — Binary Location

BN-2 — Binary Permissions

CT-1 — Container Isolation

CT-2 — Container Volumes

CT-3 — Container Image Pinning

CT-4 — Sigstore Attestation

CT-5 — Container Registry

CT-6 — Container Signature

PH-3 — OAuth / HTTP Auth

PM-1 — Package Vulnerabilities

PM-2 — Package Malware

PM-3 — Source Repository

PM-5 — Typosquatting

PM-6 — Package Distribution

PM-8 — Unscoped Variant