Skip to main content
Glama
CSOAI-ORG

meok-mcp-injection-scan-mcp

meok-mcp-injection-scan-mcp MCP 서버 MCP 레지스트리 PyPI

meok-mcp-injection-scan-mcp MCP 서버

meok-mcp-injection-scan-mcp

PyPI 버전 PyPI 다운로드 라이선스: MIT MEOK AI Labs

2026년 4월 CVE 웨이브에서 공개된 프롬프트 인젝션 / 도구 오염 / SSRF 클래스에 대해 모든 MCP 서버를 스캔하세요.

pip install meok-mcp-injection-scan-mcp

이 도구가 존재하는 이유

2026년 4월은 MCP에게 힘든 달이었습니다. Anthropic은 약 7,000개의 공개 서버(약 1억 5천만 다운로드)에 영향을 미치는 "설계상(by-design)" MCP RCE 클래스를 발표했습니다. mcp-server-git은 CVE 체인을 배포했고, DockerDash는 인젝션 체인에 의해 뚫렸습니다. 도구 설명 프롬프트 인젝션("도구 오염")은 모든 주요 MCP 호스트를 대상으로 입증되었습니다.

운영 환경에서 MCP 서버를 실행 중이거나 도입 전 감사를 수행하는 경우, 2026년 4월 공개된 패턴을 식별하는 빠른 스캔이 필요합니다. 이 MCP가 바로 그 스캔 도구입니다.

Related MCP server: agent-audit

검사 항목

5단계 심각도 등급에 걸친 30개 이상의 표준 규칙:

  • CRITICAL(치명적) — 직접적인 RCE, 시스템 프롬프트 재정의, 자격 증명 유출 패턴, 기본값의 셸 메타 문자, file:// / 내부 네트워크 URL (DockerDash 169.254.169.254 메타데이터 피벗 벡터).

  • HIGH(높음) — 인코딩된 페이로드, 에이전트의 명령형 지시문, 공급망 프롬프트, 환경 변수 참조, 도구 섀도잉.

  • MEDIUM(중간) — 긴급성 / 권위 언어, additionalProperties=true, 제한 없는 문자열, 도구 이름 사칭.

  • LOW(낮음) — 지나치게 긴 설명, 너비가 0인 문자 / 양방향 재정의 문자 (U+202E PoC 벡터).

적용 범위: OWASP LLM Top 10, GenAI Red Team v1, 2026년 4월 Anthropic MCP RCE 공개 내용 및 mcp-server-git CVE 체인.

노출된 도구

도구

목적

scan_mcp_url(url)

원격 MCP 서버의 도구 목록을 가져와 스캔

audit_tool_descriptions(tools_json)

붙여넣은 JSON 도구 목록 스캔 (인증이 필요한 서버)

signed_safety_report(subject, findings_json, score, note)

조달 등급의 서명된 인증서 발행 (Pro 등급)

list_rules()

구독 전 전체 규칙 카탈로그 검사

pricing()

구독 링크 + 등급 비교

가격

등급

가격

제공 사항

무료

£0

일일 5회 스캔, 서명된 보고서 없음

Starter

£29/월

무제한 스캔 + 서명된 보고서

Pro

£79/월

+ 예약 재스캔 + 48시간 지원

Enterprise

£1,499/월

+ 맞춤형 규칙 팩 + 4시간 SLA

모든 서명된 인증서는 https://meok-attestation-api.vercel.app/verify/<cert_id>에 저장되며, 감사자와 조달 팀은 계정 없이 확인할 수 있습니다.

제공되지 않는 기능

이 도구는 정적 패턴 스캐너입니다. 동적 오염 분석을 실행하거나, 적대적 입력으로 서버를 퍼징하거나, 인간 레드팀을 대체하지 않습니다. 이 도구는 5초 만에 무료로 감사의 첫 80%를 수행합니다.

MEOK AI Labs 제작

1인 창업자. 런던. PyPI에 234개의 MCP 패키지. meok-attestation-api.vercel.app에서 실시간 서명 인프라 운영. 스토어프론트 councilof.ai. 카탈로그 확인: https://meok-attestation-api.vercel.app/catalogue.


배포 채널

Install Server
A
license - permissive license
A
quality
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Scans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.
    19
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Security scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.
    48
    2
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    Automated security red-team for any MCP server that scans manifests against OWASP LLM Top 10 and MCP-specific risks, returning a 0-100 hardening score and HMAC-signed report.
    7
    MIT

View all related MCP servers

Related MCP Connectors

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

  • Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

  • Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/CSOAI-ORG/meok-mcp-injection-scan-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server