Audit MCP tool definitions
audit_server_toolsScan selected MCP servers for tool poisoning, shadowing, and rug pulls; inspect names, descriptions, and schemas while never calling the tools.
Instructions
Connects to the selected MCP servers, lists their tools, and checks every name, description and schema string for tool poisoning (instruction overrides, concealment requests, hidden tags, invisible Unicode, sensitive file paths, exfiltration wording, encoded payloads), cross-server tool shadowing, and changes since the tools were last pinned (rug pulls). Never calls the scanned tools.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| servers | Yes | Server names to scan, optionally as "scope:name" (e.g. "project:github"). Use ["*"] for all. | |
| project_dir | No | ||
| confirm_launch | Yes | Must be true. Scanning starts each server process (stdio) or connects to it (HTTP); only initialize and tools/list are sent and no tool is called. Ask the user first. | |
| timeout_seconds | No |