

SAFE-MCP Scanner Project
SAFE-MCP Scanner Project: Weekly Hackathon & Open Source Meetup
We’re kicking off a weekly open-source hackathon series around the SAFE-MCP Scanner, and we’d love to have you join us.
SAFE-MCP is now part of the Linux Foundation and supported by the OpenID Foundation, and the scanner is quickly becoming one of the most important pieces of the ecosystem. It helps detect real attack vectors in MCP servers and AI agents — things like tool poisoning, overscoped permissions, code execution risks, confused deputy issues, unsafe prompts, and many more.
If you want to see the project we’re working on, here’s the repo:
👉 https://github.com/SAFE-MCP/scanner
Every week, we come together to build new scanning modules, improve detection logic, discuss SAFE-MCP techniques, and generally push the scanner forward. It’s very collaborative. People jump in with ideas, PRs, mini demos, or just to learn how MCP security works.
You don’t need to be an expert to join.
Security folks, LLM engineers, cloud people, students, and just curious contributors are all welcome. If you’re trying to get deeper into AI agent security, this is honestly one of the best ways to do it.
What we typically do each week:
Work on open issues and roadmap items for the scanner
Add checks for new SAFE-MCP techniques
Improve static + runtime scanning
Review PRs and help new contributors get started
Share attack demos and real examples from MCP systems
Hang out and build something meaningful together
Why join?
Because this is a chance to help shape how the industry secures AI agents.
Your contributions will go directly into a Linux Foundation project and be used by real organizations building on MCP.
Details
Format: Weekly online hackathon / working session
Where: Online
Open to: Anyone who wants to contribute
If you’re interested in AI agents, security, or just want to work on something impactful with a fun group of people, come build with us.