Skip to main content
Glama
CSOAI-ORG

meok-mcp-injection-scan-mcp

meok-mcp-injection-scan-mcp MCP 服务器 MCP 注册表 PyPI

meok-mcp-injection-scan-mcp MCP 服务器

meok-mcp-injection-scan-mcp

PyPI 版本 PyPI 下载量 许可证: MIT MEOK AI Labs

扫描任何 MCP 服务器,以检测 2026 年 4 月 CVE 浪潮中披露的提示词注入 / 工具中毒 / SSRF 类漏洞。

pip install meok-mcp-injection-scan-mcp

为什么存在此工具

2026 年 4 月对 MCP 来说是糟糕的一个月。Anthropic 发布了一种“设计使然”的 MCP RCE 类漏洞,影响了约 7,000 个公共服务器(约 1.5 亿次下载)。mcp-server-git 发布了一个 CVE 链。DockerDash 被注入链攻破。针对每个主流 MCP 主机的工具描述提示词注入(“工具中毒”)都得到了证实。

如果您在生产环境中运行 MCP 服务器,或者在采用前进行审计,您需要一个快速扫描工具来标记 2026 年 4 月披露中所针对的模式。此 MCP 就是该扫描工具。

Related MCP server: agent-audit

它检查什么

30 多条规范规则,分为 5 个严重性等级:

  • 严重 (CRITICAL) — 直接 RCE、系统提示词覆盖、凭据窃取模式、默认值中的 shell 元字符、file:// / 内部网络 URL(DockerDash 169.254.169.254 元数据透视向量)。

  • 高 (HIGH) — 编码载荷、代理端的命令式指令、供应链提示词、环境变量引用、工具遮蔽。

  • 中 (MEDIUM) — 紧迫性 / 权威性语言、additionalProperties=true、无界字符串、工具名称冒充。

  • 低 (LOW) — 过长的描述、零宽 / 双向覆盖字符(U+202E PoC 向量)。

覆盖范围对应:OWASP LLM Top 10、GenAI Red Team v1、2026 年 4 月 Anthropic MCP RCE 披露以及 mcp-server-git CVE 链。

暴露的工具

工具

用途

scan_mcp_url(url)

获取远程 MCP 服务器的工具列表并进行扫描

audit_tool_descriptions(tools_json)

扫描粘贴的 JSON 工具列表(针对受身份验证保护的服务器)

signed_safety_report(subject, findings_json, score, note)

签发采购级签名证书(Pro 等级)

list_rules()

在订阅前查看完整的规则目录

pricing()

订阅链接 + 等级对比

定价

等级

价格

您将获得

免费

£0

每天 5 次扫描,无签名报告

入门

£29/月

无限扫描 + 签名报告

专业

£79/月

+ 定期重新扫描 + 48 小时支持

企业

£1,499/月

+ 自定义规则包 + 4 小时 SLA

每份签名证书都位于 https://meok-attestation-api.vercel.app/verify/<cert_id> — 审计员和采购团队无需账户即可确认。

您不会获得什么

这是一个静态模式扫描器。它不会运行动态污点分析,不会使用对抗性输入对服务器进行模糊测试,也不会取代人类红队。它是审计的前 80%,在 5 秒内完成,且免费。

由 MEOK AI Labs 构建

独立创始人。伦敦。PyPI 上有 234 个 MCP 包。实时签名基础设施位于 meok-attestation-api.vercel.app。店面 councilof.ai。获取目录:https://meok-attestation-api.vercel.app/catalogue


分发渠道

Install Server
A
license - permissive license
A
quality
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Scans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.
    19
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Security scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.
    48
    2
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    Automated security red-team for any MCP server that scans manifests against OWASP LLM Top 10 and MCP-specific risks, returning a 0-100 hardening score and HMAC-signed report.
    7
    MIT

View all related MCP servers

Related MCP Connectors

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

  • Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

  • Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/CSOAI-ORG/meok-mcp-injection-scan-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server