MCPShield

by mcpshield-dev

Not rated
GitHub

About

Security scanner for MCP servers — detects tool poisoning, prompt injection, and 90+ vulnerability patterns

Details

Author
mcpshield-dev
Categories
Developer Tools, Security, AI

Setup

Install MCPShield in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/mcpshield-dev/mcpshield

Follow the installation instructions in the repository README, then restart your MCP client.

Scan MCP servers and GitHub repositories for security vulnerabilities.

Powered byMCPShield— the MCP security scanner with 59+ detection rules covering the OWASP MCP Top 10.

Get a free API key atmcpshield.co/settings, then:

# Scan an HTTP MCP server mcpshield scan --url https://mcp-server.example.com/mcp # Scan a GitHub repository mcpshield scan --github https://github.com/user/repo # JSON output (for CI/CD) mcpshield scan --url https://mcp-server.example.com/mcp --json # Filter by severity mcpshield scan --url https://mcp-server.example.com/mcp --severity high

- 0— Scan completed, no critical findings
- 1— Error (invalid key, rate limit, scan failure)
- 2— Scan completed with critical findings

- MCPSHIELD_API_KEY— API key (alternative tomcpshield auth)
- MCPSHIELD_API_URL— Custom API endpoint (for self-hosted)

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

EU AI Act compliance scanner for Python AI agents — 10 tools for scanning, analysis, and remediation

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning with Cycode.

Require a named human's offline-verifiable approval before an AI agent takes an irreversible action — payment release, record change, deploy. Two-person rule, Ed25519 Trust Receipts, IETF-drafted, Apache-2.0.

Six-gate governance for AI agents: PROCEED/PAUSE/HALT decisions with hash-chained audit trails.

Remote MCP server (Streamable HTTP) at https://mcp.agenticrail.nz/ — deterministic step-order enforcement for AI agents. evaluate_step returns ALLOW or DENY before a step runs; verify_receipt proves a sequence's Ed25519-signed, hash-chained receipt chain is intact. No auth required: omit the bearer token and calls run on the public demo key. That first clause matters — the form has no "remote/hosted" field, and putting the endpoint in the description is the convention on that list ("Fully REMOTE! Just use…"). The rest mirrors your own server card verbatim, so the listing and the card can't drift.

Deterministic security preflight for AI agents. Check URLs, files and shell commands before acting.

EXIF for AI. AKF embeds trust scores, source provenance, and compliance metadata into every file your AI touches — DOCX, PDF, images, code, and 20+ formats. 9 MCP tools: stamp, inspect, trust, audit, scan, embed, extract, detect. Audit against EU AI Act, SOX, HIPAA, NIST in one command.

Arcjet is the runtime security platform that ships with your AI code.

A pre-action risk gate your AI agent calls before any irreversible action — returns a risk score, named red flags, and a gate: proceed / confirm / human-required.

Remediate vulnerabilities found by Contrast products using LLM and Coding Agent capabilities.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.