SmeltSecSmeltSec
    Features
    |Security
    |How It Works
    |Pricing
    |Docs
    |Blog
    |About
    npm

    Product

    FeaturesSecurityPricingHow It WorksDocumentation

    Resources

    Quick StartAPI ReferenceCLI ReferenceLeaderboardBlogChangelogGitHubnpm (@smeltsec/cli)npm (@smeltsec/core)

    Company

    PrivacyTerms

    SmeltSec
    © 2026 SmeltSec. Open source CLI · Proprietary SaaS.
    PrivacyTerms
    MCP SERVER PLATFORM

    Generate.. Secure.. Maintain..

    From prompt to production in under 60 seconds. SmeltSec generates servers, scans them with 16 security scanners across 2 gates, monitors upstream changes, and syncs configs to every major AI client.

    $ npx smeltsec scan ./my-serverlive on npm →
    LIVE
    ›scoring XiaoYouChR/Ghost-Downloader-3›scoring argilla-io/argilla›scoring navdeep-G/samplemod›scoring standard/standard›scoring h2oai/h2o-llmstudio›scoring react-boilerplate/react-boilerplate›scoring macanv/BERT-BiLSTM-CRF-NER›scoring statelyai/xstate›scoring microsoft/muzic›scoring elsewhencode/project-guidelines›scoring quantumlib/Cirq›scoring Bitwise-01/Instagram-›scoring bigint/hey›scoring feder-cr/Jobs_Applier_AI_Agent_AIHawk›scoring googlemaps/google-maps-services-python›scoring vuejs/vue-cli›scoring tencentmusic/cube-studio›scoring qubvel/segmentation_models›scoring helm/helm›scoring pyinfra-dev/pyinfra›scoring corna/me_cleaner›scoring aosabook/500lines›scoring google/google-ctf›scoring roboflow/sports›scoring gd3kr/BlenderGPT›scoring CopilotKit/CopilotKit›scoring khast3x/h8mail›scoring minimaxir/textgenrnn›scoring hashicorp/consul›scoring wireviz/WireViz›scoring XiaoYouChR/Ghost-Downloader-3›scoring argilla-io/argilla›scoring navdeep-G/samplemod›scoring standard/standard›scoring h2oai/h2o-llmstudio›scoring react-boilerplate/react-boilerplate›scoring macanv/BERT-BiLSTM-CRF-NER›scoring statelyai/xstate›scoring microsoft/muzic›scoring elsewhencode/project-guidelines›scoring quantumlib/Cirq›scoring Bitwise-01/Instagram-›scoring bigint/hey›scoring feder-cr/Jobs_Applier_AI_Agent_AIHawk›scoring googlemaps/google-maps-services-python›scoring vuejs/vue-cli›scoring tencentmusic/cube-studio›scoring qubvel/segmentation_models›scoring helm/helm›scoring pyinfra-dev/pyinfra›scoring corna/me_cleaner›scoring aosabook/500lines›scoring google/google-ctf›scoring roboflow/sports›scoring gd3kr/BlenderGPT›scoring CopilotKit/CopilotKit›scoring khast3x/h8mail›scoring minimaxir/textgenrnn›scoring hashicorp/consul›scoring wireviz/WireViz
    Join developers building MCP servers the right way
    TRUST REGISTRY

    500 open-source repos scored

    Independent security and quality scores across the most-starred public MCP-relevant repos. Updated daily.

    500
    Repos scored
    88
    Avg security
    50
    Avg quality
    100
    Top score
    THE THREAT LANDSCAPE

    MCP is shipping faster than its security.

    We ran a 16-scanner pipeline across the most-starred public MCP-relevant repos — covering SAST, secret leakage, dependency CVEs, MCP tool poisoning, prompt injection, and supply-chain attacks. Two-thirds shipped with at least one B-grade or worse finding. The MCP ecosystem is growing faster than the tooling that should protect it. SmeltSec is the security layer underneath every server we generate, monitor, and score.

    Pipeline · 16 scanners
    Semgrep CEGitleaksOSV-ScannerMCP-ScanTool poisoningPrompt injectionTrojan sourceSupply chain
    HOW IT WORKS

    Three Steps to Production

    1

    Describe Your API

    Use natural language, import a GitHub repo, or paste an OpenAPI spec. 60 seconds to production-ready code.

    2

    Generate & Scan

    16 security scanners run in 2 gates — pre-generation and post-generation. Critical findings block delivery.

    3

    Deploy & Monitor

    Link a GitHub repo for automatic change detection. Track usage analytics. Sync configs to every major AI client.

    CAPABILITIES

    Built for Every Workflow

    Chat AI client integration

    Chat Interface

    Describe in natural language what your MCP server should do. Get production-ready code generated in under 60 seconds.

    • Natural language input
    • Iterative refinement
    • Preview before deploy
    • Template library
    GitHub source control integration

    GitHub Integration

    Import any GitHub repo. SmeltSec analyzes your codebase with Tree-sitter, detects changes via webhooks, and proposes surgical updates.

    • Repo import & analysis
    • Webhook change detection
    • Impact classification
    • Auto-PR proposals
    OpenAPI specification ingestion
    SECURITY

    8-Tool Security Pipeline

    Every server gets scanned twice — Gate 1 before generation (SAST, secrets, CVEs, API surface) and Gate 2 after (tool poisoning, behavioral analysis, permission escalation). Critical findings block delivery.

    SAST analysis

    SAST Analysis

    Static code analysis for vulnerabilities and anti-patterns

    Secret detection

    Secret Detection

    Scan for leaked API keys, tokens, and credentials

    CVE and dependency scanning

    CVE & Dependency

    Check dependencies against known vulnerability databases

    Tool poisoning detection

    Tool Poisoning

    Detect behavioral mismatches and permission escalation

    16 security scanners — most free forever
    QUALITY

    6-Dimension Quality Scoring

    Score any MCP server across 6 dimensions. Get auto-fix suggestions to improve LLM understanding. Gate deploys on minimum scores. 87% average improvement after applying fixes.

    Tool Descriptions
    25%
    Input Schemas
    20%
    Error Handling
    15%
    Security Posture
    20%
    Behavioral Alignment
    10%
    Documentation
    10%
    ANALYTICS

    Per-Tool Usage Visibility

    Drop-in proxy intercepts MCP calls and reports per-tool analytics: calls, latency P50/P95/P99, errors, and client distribution. 12.8K calls tracked per day on average. Set alerts and export via API, webhooks, or OpenTelemetry.

    4,953scans completed
    Past 12 weeks
    vs. hand-rolled

    Why not just wire it up yourself?

    Semgrep, Gitleaks, OSV-Scanner, and MCP-Scan are all open source. Integrating them yourself takes 2–3 engineer-months. SmeltSec gives you all sixteen scanners plus quality scoring, monitoring, and multi-client config sync in 60 seconds.

    See the full comparison →
    PRICING

    Simple, Transparent Pricing

    Start free with Gate 1 security. Upgrade for the full pipeline.

    Free
    Generate MCP servers
    $0forever
    5 CLI generations/month
    Gate 1 security scanning
    3 quality scores
    2-client config sync
    POPULAR
    TypeScript
    Next.js
    Prisma
    PostgreSQL
    Redis
    Docker
    Tree-sitter
    OpenTelemetry

    Ready to Build?

    Start generating secure MCP servers in under 60 seconds. Security scanning included on every plan.

    TOP 5 BY SECURITY SCOREView all 500 →
    #1
    py-sdk
    none server - py-sdk
    Py
    A
    100
    sec
    #2
    LAION-AI/Open-Assistant
    OpenAssistant is a chat-based assistant that understands tasks, can interact with third-party systems, and retrieve info
    Py
    A
    100
    sec
    #3
    agno-agi/agno
    Build, run, manage agentic software at scale.
    Py
    A
    100
    sec
    #4
    Shubhamsaboo/awesome-llm-apps
    Collection of awesome LLM apps with AI Agents and RAG using OpenAI, Anthropic, Gemini and opensource models.
    Py
    A
    100
    sec
    #5
    lm-sys/FastChat
    An open platform for training, serving, and evaluating large language models. Release repo for Vicuna and Chatbot Arena.
    Py
    A
    100
    sec
    GRADE DISTRIBUTION
    A
    205
    B
    295
    LANGUAGES
    TypeScript
    320
    Python
    180
    Symlink threats
    Persistence
    Network threats
    Evasion
    Env manipulation
    Indirect exec
    Dangerous files
    Typosquatting
    0
    Repos scanned
    0
    A grades
    0
    B grades
    0
    C / D / F

    OpenAPI Import

    Paste an OpenAPI spec and get a fully typed MCP server. Every endpoint becomes a tool with proper schemas and descriptions.

    • Full spec parsing
    • Auto type generation
    • Schema validation
    • Endpoint mapping
    Pre + post generation scanning
    A-F security report cards
    Auto-fix suggestions
    Less
    More
    Pro
    Full security + monitoring
    $20/month
    Unlimited generation
    Full 2-gate security pipeline
    Security report cards
    5 monitored repos
    Usage analytics (30d)
    Full API access
    Team
    Team + data infrastructure
    $50/month
    Everything in Pro
    25 monitored repos
    90-day analytics retention
    5 team members
    OpenTelemetry export
    Priority support