meok-mcp-injection-scan-mcp
meok-mcp-injection-scan-mcp
扫描任何 MCP 服务器,以检测 2026 年 4 月 CVE 浪潮中披露的提示词注入 / 工具中毒 / SSRF 类漏洞。
pip install meok-mcp-injection-scan-mcp为什么存在此工具
2026 年 4 月对 MCP 来说是糟糕的一个月。Anthropic 发布了一种“设计使然”的 MCP RCE 类漏洞,影响了约 7,000 个公共服务器(约 1.5 亿次下载)。mcp-server-git 发布了一个 CVE 链。DockerDash 被注入链攻破。针对每个主流 MCP 主机的工具描述提示词注入(“工具中毒”)都得到了证实。
如果您在生产环境中运行 MCP 服务器,或者在采用前进行审计,您需要一个快速扫描工具来标记 2026 年 4 月披露中所针对的模式。此 MCP 就是该扫描工具。
Related MCP server: agent-audit
它检查什么
30 多条规范规则,分为 5 个严重性等级:
严重 (CRITICAL) — 直接 RCE、系统提示词覆盖、凭据窃取模式、默认值中的 shell 元字符、
file:/// 内部网络 URL(DockerDash 169.254.169.254 元数据透视向量)。高 (HIGH) — 编码载荷、代理端的命令式指令、供应链提示词、环境变量引用、工具遮蔽。
中 (MEDIUM) — 紧迫性 / 权威性语言、
additionalProperties=true、无界字符串、工具名称冒充。低 (LOW) — 过长的描述、零宽 / 双向覆盖字符(U+202E PoC 向量)。
覆盖范围对应:OWASP LLM Top 10、GenAI Red Team v1、2026 年 4 月 Anthropic MCP RCE 披露以及 mcp-server-git CVE 链。
暴露的工具
工具 | 用途 |
| 获取远程 MCP 服务器的工具列表并进行扫描 |
| 扫描粘贴的 JSON 工具列表(针对受身份验证保护的服务器) |
| 签发采购级签名证书(Pro 等级) |
| 在订阅前查看完整的规则目录 |
| 订阅链接 + 等级对比 |
定价
每份签名证书都位于 https://meok-attestation-api.vercel.app/verify/<cert_id> — 审计员和采购团队无需账户即可确认。
您不会获得什么
这是一个静态模式扫描器。它不会运行动态污点分析,不会使用对抗性输入对服务器进行模糊测试,也不会取代人类红队。它是审计的前 80%,在 5 秒内完成,且免费。
由 MEOK AI Labs 构建
独立创始人。伦敦。PyPI 上有 234 个 MCP 包。实时签名基础设施位于 meok-attestation-api.vercel.app。店面 councilof.ai。获取目录:https://meok-attestation-api.vercel.app/catalogue。
分发渠道
PyPI:
pip install meok-mcp-injection-scan-mcp(此包)Apify Store (按事件付费): https://apify.com/knowing_yucca/meok-mcp-injection-scan
GitHub (源码): https://github.com/CSOAI-ORG/MEOK-LABS/tree/main/mcps/meok-mcp-injection-scan-mcp
Maintenance
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceScans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.19MIT
- AlicenseNot gradedqualityCmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.482MIT
- AlicenseNot gradedqualityCmaintenanceScans MCP servers, AI agent skills, and plugins for 68+ malicious patterns including credential exfiltration, prompt injection, and code execution.465MIT
- AlicenseBqualityBmaintenanceAutomated security red-team for any MCP server that scans manifests against OWASP LLM Top 10 and MCP-specific risks, returning a 0-100 hardening score and HMAC-signed report.7MIT
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/CSOAI-ORG/meok-mcp-injection-scan-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server