Tensorfire
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@TensorfireScan my OpenAI endpoint for jailbreak vulnerabilities"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
An MCP server, shipped as a container image, for security-testing AI models. It exposes two things behind one consistent tool interface:
garak vulnerability scanning — probe any OpenAI-compatible LLM endpoint for jailbreaks, prompt injection, toxicity, and data leakage.
URL / MCP-endpoint scanning — classify URLs for phishing/exfil traits and screen a remote MCP server's advertised tools for prompt-injection payloads.
Point any MCP client (an agent, an IDE, CI) at the server and it gets these as callable tools.
What Tensorfire is, and why we built it
AI security tooling is scattered across libraries that each bring their own CLI, config, and integration work. Wiring even one of them into an agent or a CI pipeline is repetitive glue.
Tensorfire puts that capability behind a single Model Context Protocol surface, so running a security test is a tool call rather than an integration project. This initial release keeps the scope deliberately small — an LLM vulnerability scan and URL/MCP screening — with room to add more tools over time.
Design principles:
Graceful degradation. The server always starts and always advertises its catalog. If an optional dependency is missing, the tool returns a structured "dependency unavailable" result instead of crashing.
Extensible. Tools are auto-discovered — dropping a module into
src/tensorfire/tools/adds a pack with no central wiring.Secrets stay out of tool calls. Tools that hit a live model take the name of an environment variable holding the API key, never the key itself.
Tools
Pack | Backed by | Tools |
|
| |
| built-in (MCP SDK) |
|
| built-in (offline) |
|
Plus tensorfire_catalog, which lists every pack and whether it's installed.
Clients should call it first.
Related MCP server: guardrails-mcp-server
Deploy with Docker
# Build and run. Serves streamable HTTP on http://localhost:8000/mcp.
docker compose up --builddocker-compose.yml passes target-model secrets from your shell environment
(OPENAI_API_KEY, OPENAI_BASE_URL) into the container and mounts ./workspace
read-only for any files your tools need to reach.
Without compose:
docker build -t tensorfire:latest .
docker run -p 8000:8000 \
-e OPENAI_API_KEY=your-key \
-e OPENAI_BASE_URL=https://api.openai.com/v1 \
tensorfire:latestDeploy locally (no container)
python -m venv .venv && . .venv/bin/activate
pip install -e ".[dev]" # installs the server + garak
tensorfire # serves http://localhost:8000/mcppip install pulls garak (and its ML dependencies), so the first install is
large. Everything runs in this one environment — there is no separate build
step.
Configuration
All optional, via environment variables:
Variable | Default | Purpose |
|
| bind address |
|
| port |
|
| set |
|
| log verbosity |
Verify it's up
curl -fsS http://localhost:8000/health
# {"status":"ok","server":"tensorfire","packs_total":3,"packs_ready":3}Use /health for liveness — never probe /mcp with a bare GET; it requires
the MCP handshake and returns 406 Not Acceptable by design.
Connecting a client
Any MCP client that supports streamable HTTP:
{ "mcpServers": { "tensorfire": { "url": "http://localhost:8000/mcp" } } }Clients should call tensorfire_catalog first, then call tools by name.
Running a garak scan
garak_scan defaults to a local Ollama server — no API key required.
model— the Ollama model name (e.g.llama3.1,gemma4:26b-a4b-it-q8_0).base_url— only if Ollama isn't on127.0.0.1:11434(e.g.http://ollama:11434when the server runs in another container). It's normalized to thehost:portgarak's Ollama client expects.probes— comma-separated probe families (e.g."promptinject,dan"); omit for garak's default set. Usegarak_list_probesto see what's available.
Minimal call:
{ "model": "gemma4:26b-a4b-it-q8_0", "probes": "promptinject", "generations": 1 }Testing an OpenAI-compatible endpoint instead
Set model_type to openai or openai.OpenAICompatible, base_url to the
endpoint, and api_key_env to the name of the env var (in the server's
environment) holding the key:
{
"model": "gpt-4o-mini",
"model_type": "openai",
"api_key_env": "OPENAI_API_KEY",
"probes": "promptinject"
}API keys are never tool arguments. The agent passes api_key_env — the
name of an environment variable inside the Tensorfire container that holds the
key. Provision the actual secret via docker-compose.yml or -e.
Development
pip install -e ".[dev]"
pytestThis server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityDmaintenanceMCP Server For Garak LLM Vulnerability Scanner https://github.com/EdenYavin/Garak-MCP/blob/main/README.mdLast updated56MIT
- Alicense-qualityCmaintenanceMCP server for AI agent security guardrails. Provides input validation, prompt injection detection, PII redaction, output filtering, policy enforcement, rate limiting, and comprehensive audit logging.Last updated481MIT
- Alicense-qualityBmaintenanceMCP server that provides tools to scan text and URLs for prompt injection attacks, protecting AI agents from adversarial inputs.Last updatedMIT
- AlicenseCqualityDmaintenanceSecurity scanner and MCP server that catches dangerous patterns in MCP servers and AI agent projects, such as leaked secrets, shell execution, and prompt-injection text. Runs as both a CLI and MCP server with CI-friendly severity gates.Last updated21MIT
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/cignal-ai/tensorfire'
If you have feedback or need assistance with the MCP directory API, please join our Discord server