meok-mcp-injection-scan-mcp
meok-mcp-injection-scan-mcp
2026年4月のCVE波で公開されたプロンプトインジェクション / ツールポイズニング / SSRFクラスの脆弱性について、あらゆるMCPサーバーをスキャンします。
pip install meok-mcp-injection-scan-mcpなぜこれが存在するのか
2026年4月はMCPにとって悪い月でした。Anthropicは、約7,000の公開サーバー(約1億5,000万ダウンロード)に影響を与える「設計上の」MCP RCEクラスを公開しました。mcp-server-gitはCVEチェーンを出荷しました。DockerDashはインジェクションチェーンによって侵害されました。ツール記述のプロンプトインジェクション(「ツールポイズニング」)は、すべての主要なMCPホストに対して実証されました。
MCPサーバーを本番環境で運用している場合、あるいは導入前に監査を行う場合、2026年4月の開示で対象となったパターンをフラグ立てする高速なスキャンが必要です。このMCPがそのスキャンを行います。
Related MCP server: agent-audit
チェック内容
5段階の深刻度にわたる30以上の標準ルール:
CRITICAL — 直接的なRCE、システムプロンプトのオーバーライド、認証情報の流出パターン、デフォルト設定内のシェルメタ文字、
file:/// 内部ネットワークURL(DockerDashの169.254.169.254メタデータピボットベクトル)。HIGH — エンコードされたペイロード、エージェントへの命令的指示、サプライチェーンプロンプト、環境変数参照、ツールシャドウイング。
MEDIUM — 緊急性 / 権威的な言語、
additionalProperties=true、無制限の文字列、ツール名のなりすまし。LOW — 長すぎる説明、ゼロ幅 / 双方向オーバーライド文字(U+202E PoCベクトル)。
カバレッジは、OWASP LLM Top 10、GenAI Red Team v1、2026年4月のAnthropic MCP RCE開示、およびmcp-server-git CVEチェーンに対応しています。
公開されているツール
ツール | 目的 |
| リモートMCPサーバーのツールリストを取得してスキャンする |
| 貼り付けられたJSONツールリストをスキャンする(認証が必要なサーバー用) |
| 調達グレードの署名付き証明書を発行する(Proティア) |
| サブスクライブ前にルールカタログ全体を検査する |
| サブスクリプションリンク + ティア比較 |
料金
ティア | 価格 | 内容 |
Free | £0 | 1日5スキャン、署名付きレポートなし |
Starter | 無制限スキャン + 署名付きレポート | |
Pro | + 定期的な再スキャン + 48時間サポート | |
Enterprise | + カスタムルールパック + 4時間SLA |
すべての署名付き証明書は https://meok-attestation-api.vercel.app/verify/<cert_id> に存在し、監査人や調達チームはアカウントなしで確認できます。
得られないもの
これは静的パターン・スキャナーです。動的な汚染分析を実行したり、敵対的な入力でサーバーをファジングしたり、人間のレッドチームに取って代わるものではありません。これは監査の最初の80%を、5秒で、無料で行うものです。
MEOK AI Labsによる構築
ソロ創業者。ロンドン。PyPIで234のMCPパッケージ。ライブ署名インフラストラクチャは meok-attestation-api.vercel.app。ストアフロントは councilof.ai。カタログの取得: https://meok-attestation-api.vercel.app/catalogue。
流通チャネル
PyPI:
pip install meok-mcp-injection-scan-mcp(本パッケージ)Apify Store (イベントごとの支払い): https://apify.com/knowing_yucca/meok-mcp-injection-scan
GitHub (ソース): https://github.com/CSOAI-ORG/MEOK-LABS/tree/main/mcps/meok-mcp-injection-scan-mcp
Maintenance
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceScans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.19MIT
- AlicenseNot gradedqualityCmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.482MIT
- AlicenseNot gradedqualityCmaintenanceScans MCP servers, AI agent skills, and plugins for 68+ malicious patterns including credential exfiltration, prompt injection, and code execution.465MIT
- AlicenseBqualityBmaintenanceAutomated security red-team for any MCP server that scans manifests against OWASP LLM Top 10 and MCP-specific risks, returning a 0-100 hardening score and HMAC-signed report.7MIT
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/CSOAI-ORG/meok-mcp-injection-scan-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server