MCP-Scan is a security tool that scans MCP servers for vulnerabilities including tool poisoning, prompt injection, cross-origin escalation, and rug pull attacks. Acquired by Snyk in 2026, it is the first dedicated security scanner for the MCP ecosystem. It analyzes tool descriptions, permissions, and behavior patterns to detect malicious or compromised MCP servers before they can exploit AI agents.
Alternatives to Zerobox
2 editor-selected alternatives · Zerobox overview →
source: tools.alternatives · stored order · active records only; review scores are annotations and never change membership or order
A directional evidence panel appears only when the substitute rationale, trade-offs, sources, and verification date have been recorded. Older selections without that panel remain visible but are unclassified under the new evidence contract.
Trent AI is a specialized security platform for agentic AI applications providing AI Security Posture Management that compounds with every development cycle. Scans, judges, mitigates, and evaluates AI agent security detecting threats traditional tools miss including prompt injection attacks, tool misuse, unintended autonomous actions, data exfiltration through agent chains, and privilege escalation. Offers continuous assessment with remediation plan execution through Claude Code.
Open-source Zerobox alternatives
MCP-Scan — see all open-source developer tools.
More AI Security & DevSecOps tools
same category, not editor-selected alternatives — see how Zerobox compares →
FAQ
Which Zerobox alternative is listed first?
MCP-Scan is first in the editor-selected list of 2 Zerobox alternatives and carries an editorial review score of 90/100. The stored order is editorial; review scores do not determine membership or position.
Are there open-source Zerobox alternatives?
Yes — MCP-Scan are open source.