heron
Server Details
Signed security scores for what an AI agent runs and reads: skills, MCP servers, prompts, tokens.
- Status
- Unhealthy
- Last Tested
- Transport
- Streamable HTTP
- URL
TDQS
Scored across 13 tools
Each tool has a clearly distinct purpose, from identity lookup and posture scoring to specific scans for skills, MCP servers, and user input. No two tools appear to overlap in function, and descriptions are detailed enough to avoid confusion.
All tools use the 'heron_' prefix and underscores, with a mix of noun phrases (e.g., heron_agent_identity) and verb imperatives (e.g., heron_inspect). The pattern is mostly consistent, though the mix of noun and verb forms is a minor deviation.
With 13 tools, the set is well-scoped for a security analysis service. Each tool covers a specific aspect of agent and server safety, leaving no apparent bloat or scarcity.
The tools cover core security workflows: identity, posture, red-teaming, input inspection, and verification. The inclusion of heron_score (URL citability) is slightly tangential but not a major gap. Minor missing features like batch scanning or historical comparisons prevent a perfect score.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- Changed
heron_inspect1 field changed- changed
Input schema / properties / deep / defaultPrevious value: -falseNew value: +true
1 tool update
- Added
heron_token_scan
2 tool updates
- Added
heron_agent_posture - Added
heron_inspect
11 tool updates
- First observed
heron_agent_identity - First observed
heron_agent_redteam - First observed
heron_full_report - First observed
heron_manifest - First observed
heron_mcp_scan - First observed
heron_methodology - First observed
heron_negotiate - First observed
heron_score - First observed
heron_skill_scan - First observed
heron_trust_index - First observed
heron_verify_attestation
Related MCP Connectors
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Read-only smart-contract security intelligence for autonomous agents.
Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceSecurity scanning for AI agent skills, MCP servers, and agent prompts, returning signed trust scores and detailed findings.MIT
- FlicenseNot gradedqualityDmaintenanceOn-chain trust verification for AI agent tools. Agents query skill attestations, audit levels, and risk scores before running third-party MCP servers, so you know what's safe before you execute.1-
- AlicenseNot gradedqualityAmaintenanceAudits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.2Apache 2.0
- AlicenseAqualityBmaintenanceSecurity co-pilot for AI agents. Scans for vulnerabilities like prompt injection, infinite loops, and token bombing in AI Agents, audits MCP servers, verifies AGENTS.md governance, and generates EU AI Act compliance reports.10283Apache 2.0