Identify prompt injection, tool shadowing, dangerous capabilities, and secret parameters — then generate a clear, evidence-backed risk report.
0
Detection rule families
0
OWASP MCP categories
0s
Typical scan time
0%
Advisory — config untouched
Trusted Security Statement
Prompt injection in a tool description is an unaudited channel into your agent. Scan before you connect.
Without scanning — the attack path
Developer
Finds a useful MCP tool online.
Downloads MCP
Description looks legitimate.
Agent Executes
AI obeys hidden instructions.
Prompt Injection
Unaudited channel into the agent.
Credential Leak
Secrets leave over the network.
Business Impact
Compliance, downtime, reputation.
With MCP Shield — the secure path
Developer
Same developer, same tool.
Upload MCP
JSON config — never modified.
AI Scan
Rules + optional LLM enrichment.
Threat Detection
Evidence-backed findings.
Risk Report
Score, grade, trust decision.
Safe Deployment
Clear go / no-go call.
6
detection rule families
5
OWASP MCP risk categories mapped
0
config mutations — advisory only
Scroll to scrub
How the Scan Works
Click a stage to watch the security core transform — no endless card rail.
Stage 01
Upload or paste an MCP JSON config. Schema checks confirm it looks like a real tool definition — nothing is modified.
Threat Detection
Everything the scanner checks — in one balanced grid.
Surfaces hidden instructions buried in tool descriptions before agents obey them.
Flags near-duplicate names that can steal routing from trusted tools.
Highlights exec, network, and filesystem permissions that expand blast radius.
Finds credential-shaped fields and secret-handling patterns in schemas.
Weighted 0–100 score with grade and confidence for deployment decisions.
Evidence spans, remediations, and executive language ready for review.
Product Preview
Mock marketing data only — your real scans stay private and separate.
NOT TRUSTED
Confidence 96% · Do not deploy
F
Grade
MCP03
OWASP
2
Findings
Deep dives
Upload a config or try a poisoned sample — advisory only, never modified.
Scanning Console
Paste JSON, drop a file, or try an Acme DevTools sample. Advisory only — your config is never modified.
MCP JSON
Paste a config or load a sample to begin.
Sample configuration
5 experimental MCPs: 1 safe, 4 OWASP-mapped breaches
Drop MCP JSON here
or choose a file from disk