MCPShield
About
Security scanner for MCP servers — detects tool poisoning, prompt injection, and 90+ vulnerability patterns
Details
- Author
- mcpshield-dev
- Categories
- Developer Tools, Security, AI
Jump to
Setup
Install MCPShield in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/mcpshield-dev/mcpshield
Follow the installation instructions in the repository README, then restart your MCP client.
Scan MCP servers and GitHub repositories for security vulnerabilities.
Powered byMCPShield— the MCP security scanner with 59+ detection rules covering the OWASP MCP Top 10.
Get a free API key atmcpshield.co/settings, then:
# Scan an HTTP MCP server mcpshield scan --url https://mcp-server.example.com/mcp # Scan a GitHub repository mcpshield scan --github https://github.com/user/repo # JSON output (for CI/CD) mcpshield scan --url https://mcp-server.example.com/mcp --json # Filter by severity mcpshield scan --url https://mcp-server.example.com/mcp --severity high
- 0— Scan completed, no critical findings
- 1— Error (invalid key, rate limit, scan failure)
- 2— Scan completed with critical findings
- MCPSHIELD_API_KEY— API key (alternative tomcpshield auth)
- MCPSHIELD_API_URL— Custom API endpoint (for self-hosted)
This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.
EU AI Act compliance scanner for Python AI agents — 10 tools for scanning, analysis, and remediation
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning with Cycode.
Require a named human's offline-verifiable approval before an AI agent takes an irreversible action — payment release, record change, deploy. Two-person rule, Ed25519 Trust Receipts, IETF-drafted, Apache-2.0.
Six-gate governance for AI agents: PROCEED/PAUSE/HALT decisions with hash-chained audit trails.
Remote MCP server (Streamable HTTP) at https://mcp.agenticrail.nz/ — deterministic step-order enforcement for AI agents. evaluate_step returns ALLOW or DENY before a step runs; verify_receipt proves a sequence's Ed25519-signed, hash-chained receipt chain is intact. No auth required: omit the bearer token and calls run on the public demo key. That first clause matters — the form has no "remote/hosted" field, and putting the endpoint in the description is the convention on that list ("Fully REMOTE! Just use…"). The rest mirrors your own server card verbatim, so the listing and the card can't drift.
Deterministic security preflight for AI agents. Check URLs, files and shell commands before acting.
EXIF for AI. AKF embeds trust scores, source provenance, and compliance metadata into every file your AI touches — DOCX, PDF, images, code, and 20+ formats. 9 MCP tools: stamp, inspect, trust, audit, scan, embed, extract, detect. Audit against EU AI Act, SOX, HIPAA, NIST in one command.
Arcjet is the runtime security platform that ships with your AI code.
A pre-action risk gate your AI agent calls before any irreversible action — returns a risk score, named red flags, and a gate: proceed / confirm / human-required.
Remediate vulnerabilities found by Contrast products using LLM and Coding Agent capabilities.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.




