Offensive MCP server auditor — detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.
-
Updated
Mar 11, 2026 - TypeScript
Offensive MCP server auditor — detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.
Real-time security layer protecting AI Agents from Confused Deputy attacks, malicious MCP payloads, and Indirect Prompt Injection.
Live PoC: MCP rug pull attack that steals AI agent credentials mid-session and how to block it in 3 lines of code.
Local static scanner for MCP setup, config, prompts, and workflow trust.
Supply chain security for MCP — pin, hash, detect drift in your AI tool chains
Security scanner for AI agent tools — detect tool poisoning, data exfiltration, and supply chain attacks in MCP servers and agent skills
Add a description, image, and links to the tool-poisoning topic page so that developers can more easily learn about it.
To associate your repository with the tool-poisoning topic, visit your repo's landing page and select "manage topics."