project-shield
Project Shield
Security scanner for AI coders and MCP users. It checks projects and AI-agent configuration for exposed secrets, PII, insecure MCP settings, prompt injection, and risky Claude Code hooks.
Run the free scan
npx project-shield scan ./my-projectProject Shield v2.0.0 runs locally and includes security grading, fix guidance, and AI-agent environment auditing.
Related MCP server: agent-audit
Free and Pro
Feature | Free | Pro |
Project scans | 5/month | 50/month |
Environment audits | 3/month | 20/month |
Fix-it guidance | Top 3 summaries | All guides with code and references |
Badge | Watermarked | Clean badge with UUID and verification URL |
Evidence Pack | Not included | JSON + PDF with integrity seal |
PII findings | Count only | File and line details |
Project Shield Pro is $29/month and is delivered through an automated Polar license-key benefit.
The Polar checkout displays Clouvel, the publisher account for Project Shield. Taxes, when applicable, are calculated by Polar from the buyer's billing address and shown before payment.
Commands
# Scan a project
npx project-shield scan ./my-project
# Audit the local AI coding environment
npx project-shield audit
# Activate a Polar-issued Pro license
project-shield activate PSH-XXXX-XXXX-XXXX-XXXX
# Check license status
project-shield statusWhat Pro unlocks
Full fix-it guides with code examples and references
JSON and PDF Evidence Packs
Clean badges with UUID and verification URL
Full Claude Code environment checks and hooks analysis
Higher monthly scan and audit limits
Security notes
Run scans only on projects you own or are authorized to inspect.
Review findings before changing code or configuration.
Never paste secrets or customer data into public issues.
License
MIT
This server cannot be installed
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceScans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.19MIT
- AlicenseNot gradedqualityCmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.482MIT
- AlicenseAqualityCmaintenanceScans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.5MIT
- AlicenseNot gradedqualityCmaintenanceScans MCP servers, AI agent skills, and plugins for 68+ malicious patterns including credential exfiltration, prompt injection, and code execution.465MIT
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Whitening-Sinabro/project-shield-docs'
If you have feedback or need assistance with the MCP directory API, please join our Discord server