MCP Scanner
Model Context Protocol security

See what a tool description is really telling your agent.

Point this at an MCP endpoint. It reads every tool the server exposes, checks the descriptions and schemas for planted instructions, then runs a live agent against the server with poisoned tool output to see whether the agent obeys.

Live probes send hostile text to the server you name and call its tools for real. Run them against servers you own or have permission to test.

Static analysis

Every tool description and schema string, checked against rules for planted instructions, forged system markers, and invisible characters.

Live agent probe

A real agent calls the tool, the genuine result comes back carrying a canary payload, and the scanner watches whether the model obeys.

Measured, not asserted

The detector is scored against a labeled corpus on every commit — precision, recall and false-positive rate, not vibes.

Recent scans

No scans yet. Paste an endpoint above to run the first one.