Plutonium

Scan your MCP before launch

Check an MCP for risky capabilities, prompt injection, code execution, and other security issues before you use it.

MCP source type

Enter a public npm package name, optionally with an exact version or npm tag.

What can I enter?

Accepted

  • firecrawl-mcpPackage name
  • @notionhq/notion-mcp-serverScoped package
  • [email protected]Exact version
  • @notionhq/[email protected]Scoped package with version
  • @playwright/mcp@latestnpm tag, such as latest or next

If no version is provided, we scan the latest published version and pin the exact version in your report.

Not supported

  • npm page URLs
  • npm install commands
  • Private packages
  • GitHub URLs or local paths
  • Version ranges such as ^1.2.3
  • Values containing spaces