Offensive MCP server auditor — detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.
-
Updated
Mar 12, 2026 - TypeScript
Offensive MCP server auditor — detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.
🛡️ Security scanner for AI agents, MCP servers & plugins — 30 rules, AST taint tracking, cross-file analysis, kill chain detection. Free & open source alternative to Snyk Agent Scan.
Real-time security layer protecting AI Agents from Confused Deputy attacks, malicious MCP payloads, and Indirect Prompt Injection.
Live PoC: MCP attacks that compromise AI agents mid-session and how to block them in a few lines of code.
Local static scanner for MCP setup, config, prompts, and workflow trust.
Open-source security platform for AI agents -- audits skills before install, monitors 24/7, shares threat intelligence across all users. | AI Agent 開源安全平台 -- 安裝前審計 skill、24/7 即時監控、社群共享威脅情報。
Supply chain security for MCP — pin, hash, detect drift in your AI tool chains
Security scanner for AI agent tools — detect tool poisoning, data exfiltration, and supply chain attacks in MCP servers and agent skills
Add a description, image, and links to the tool-poisoning topic page so that developers can more easily learn about it.
To associate your repository with the tool-poisoning topic, visit your repo's landing page and select "manage topics."