MCP Tool Security Inspector
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP Tool Security InspectorScan this MCP tool definition for security risks."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP Tool Security Inspector
Explainable, deterministic static analysis for Model Context Protocol tool metadata.
Security disclaimer: The MCP Tool Security Inspector is a defensive analysis tool. It identifies indicators that may warrant review but does not establish whether an MCP tool or server is definitively malicious or safe.
Screenshot placeholders
screenshots/clean-scan.png— clean catalog summaryscreenshots/suspicious-scan.png— finding evidence and recommendationsscreenshots/drift-comparison.png— baseline drift table
Related MCP server: mcp-guardian
The problem
AI clients often expose MCP tool names, descriptions, schemas, and metadata to a model. That catalog is a trust boundary: misleading instructions, concealed capabilities, unexpected credential fields, or later schema changes deserve review even when no tool has run. mcpsec analyzes that static surface without invoking tools or fetching metadata URLs.
What are MCP and MCP tools?
Model Context Protocol is an open protocol for connecting AI applications to servers that expose context and capabilities. A tool is a named callable capability with descriptive metadata and JSON Schemas for inputs and optional outputs. This release targets the official 2026-07-28 specification and stable official Python SDK v2, while tolerating older common catalog envelopes.
Threat model and tool poisoning
Tool metadata can influence both human approval and model tool selection. A malicious publisher, compromised server, dependency, or accidental configuration could add model-directed instructions, concealment wording, privileged fields, or obfuscation. See threat model and tool poisoning.
Features
Single-tool, array, direct
toolsobject, and JSON-RPCtools/listresponse loadingUnknown-field preservation and Unicode NFC normalization
Stable UTF-8 canonical JSON and SHA-256 full/component fingerprints
Privacy-conscious baselines and field-level drift classification
Instruction override, concealment, sensitive data, schema, mismatch, obfuscation, and capability detectors
Strict data-only YAML rules using safe loading and bounded literal matching
Explainable, capped risk scores from 0–100
Rich terminal, JSON, CSV, and SARIF 2.1.0 output
Evidence redaction and spreadsheet formula-injection mitigation
CI severity thresholds with documented exit codes
No telemetry, tool calls, icon downloads, URL fetching, or metadata execution
Architecture
flowchart LR
A["Hostile JSON catalog"] --> B["Bounded loader"]
B --> C["Normalizer"]
C --> D["Canonicalizer + SHA-256"]
C --> E["Detectors + data-only rules"]
E --> F["Capped risk engine"]
D --> G["Baseline comparator"]
F --> H["Terminal / JSON / CSV / SARIF"]
G --> HThe implementation never sends catalog content to a model and never executes scanned values. See architecture.
Installation
python -m venv .venv
# Windows: .\.venv\Scripts\Activate.ps1
# Linux/macOS: source .venv/bin/activate
python -m pip install --upgrade pip
python -m pip install -e ".[dev]"
mcpsec --helpSee PREPARATION.md for the audited environment and editor recommendations.
Quick start and scans
mcpsec scan examples/clean_tools.json
mcpsec scan examples/suspicious_tools.json
mcpsec scan examples/mixed_tools.json --format json
mcpsec scan examples/suspicious_tools.json --format csv --output report.csv --redact
mcpsec scan examples/suspicious_tools.json --format sarif --output report.sarif
mcpsec scan examples/mixed_tools.json --rules rules/default_rules.yml --fail-on highStructured reports contain no ANSI escape sequences. CSV fields beginning with spreadsheet formula characters are prefixed with an apostrophe.
Baseline and schema-drift workflow
mcpsec baseline examples/clean_tools.json --output baseline.json
mcpsec compare examples/clean_tools.json --baseline baseline.json
mcpsec compare examples/changed_tools.json --baseline baseline.json --verbose
mcpsec fingerprint examples/clean_tools.jsonThe changed fixture modifies calculator description and input schema and adds unit_converter. Baselines store hashes and structural summaries, not full descriptions, defaults, or example secrets. See schema drift.
Risk scoring
Each finding's configured contribution is multiplied by confidence. Contributions are grouped and capped at 35 per category; category risks are combined using 100 × (1 − Π(1 − category/100)). Two documented correlations add bounded synergy: instruction override + concealment adds 10, and concealment + sensitive-data language adds 7. The final value is rounded and capped at 100.
Bands: 0–19 informational, 20–39 low, 40–59 medium, 60–79 high, 80–100 critical. A score prioritizes review; it is not a probability or verdict.
Rules and explainability
mcpsec rules list
mcpsec rules validate rules/default_rules.yml
mcpsec explain SEC-001Custom rules allow ID, name, category, fields, literal patterns, severity, confidence, score, recommendation, rationale, benign usage, and enabled state. They cannot contain Python expressions, shell commands, imports, templates, or executable regex. See detection rules.
Output formats
The terminal table summarizes tool counts, clean/affected totals, severity, risk, rule IDs, evidence, and recommendations. JSON preserves typed findings; CSV is analysis-friendly; SARIF provides GitHub code-scanning-compatible structure for future integration.
CI use
Exit codes are 0 for no configured threshold exceeded, 1 for a completed scan exceeding --fail-on, 2 for invalid user input, and 3 for an internal failure.
mcpsec scan catalog.json --fail-on mediumThe included GitHub Actions workflow installs Python, runs Ruff lint/format checks, mypy, and pytest with coverage. It requires no secrets, does not connect to servers, and does not publish.
Testing
ruff check .
ruff format --check .
mypy src
python -m pytest --cov=mcpsec --cov-report=term-missing --cov-report=htmlOn Windows, scripts\test.ps1 -q runs the correct virtual-environment interpreter even when the environment is not activated. Use scripts\dev-inspector.ps1 for the local demonstration server; see the sample-server guide. The /sandbox address printed by Inspector is an internal iframe endpoint, not the main user interface.
Tests cover input shapes, Unicode, canonicalization, hashes, baselines, drift, detectors, risk caps, rule validation, safe YAML, structured reports, CSV neutralization, and CLI exit codes.
Security model and false positives
All input is untrusted data. Files are size-bounded; strings are length-bounded; YAML uses safe_load; schema content is validated but never evaluated; custom matching is literal and bounded; terminal escape bytes are neutralized; reporters do not render HTML. A finding says “suspicious” or “requires review,” never asserts compromise. Every built-in rule documents its rationale, benign triggers, and guidance through mcpsec explain.
See SECURITY.md, detection rules, and limitations.
Limitations
A clean scan does not establish trust; a suspicious scan does not prove malicious intent. Static metadata may differ from runtime implementation. Heuristics cannot understand every language, business context, schema reference, or prompt-injection variation. Human review and runtime controls remain necessary.
Roadmap
v0.2: opt-in, allowlisted local catalog retrieval using SDK
tools/listonlyRicher MCP 2026-07-28
x-mcp-headervalidationSigned baseline envelopes and baseline policy profiles
Rule-pack versioning, suppressions with justification, and delta SARIF
Additional language-aware heuristics and corpus-driven false-positive measurement
Contributing and license
See CONTRIBUTING.md. Security reports follow SECURITY.md. Licensed under the MIT License.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceStatic security linter for MCP servers. Scans tool definitions for vulnerabilities (path traversal, SQL injection, SSRF), scores description quality, and auto-rewrites descriptions for safer agent tool selection.210MIT
- AlicenseNot gradedqualityBmaintenanceScans MCP tool descriptions for prompt injection attacks, including cross-tool instructions, privilege escalation, and data exfiltration patterns. It can be used as a CLI scanner or integrated as an MCP server itself.3106MIT
- AlicenseNot gradedqualityAmaintenanceSecurity scanner for MCP servers — vet an MCP before you wire it into an agent. Detects prompt-injection, credential exfiltration (via taint analysis), RCE, and supply-chain risks, and catches cross-server exfil chains no single server reveals. Zero-dependency local CLI, SARIF output, CI-gateable, no account.43MIT
- AlicenseNot gradedqualityBmaintenanceProvides audit_plugin_health and prepare_semantic_review tools for deterministic inspection of Codex plugins and Agent Skills, generating evidence-backed reports without executing or transmitting target code.1MIT
Related MCP Connectors
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Deterministic validation for AI-generated artifacts: JSON Schema, OpenAPI response, SQL syntax.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/danveil/mcp-security-inspector'
If you have feedback or need assistance with the MCP directory API, please join our Discord server