Medusa
UnclaimedAI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an always-on AI attack-signature scanner and native Rust & PHP rules. Also: medusa scan --git to vet any repo, medusa secrets scan for leaked API keys. 40,000+ patterns, zero setup.
Set up this server
01 / Choose your client
02 / Before you connect
Authentication is not specified. Check the project instructions before connecting.
Project instructions03 / Add the configuration
claude mcp add --transport stdio 'medusa' -- 'uvx' 'medusa-security'04 / Check it in your client
Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.
More in Security
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
Tool change history
FAQ
Questions about Medusa MCP Server
- How do I connect Medusa MCP Server to Claude?
- Run `claude mcp add medusa -- uvx medusa-security` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
- Is Medusa MCP Server free?
- The listed licence is AGPL-3.0. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can Medusa MCP Server do?
- MCPVault has not yet recorded the tool list for Medusa MCP Server; it is captured when the server passes a live MCP handshake. The description above is what the project publishes.