tooltrust-scanner

MCP serverAI & models

Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.

This server has no hosted endpoint yet, so ahel can't serve it. You can still add it. It stays paused until ahel can serve it.

Serve it through your gateway

One link, every agent. Your own credentials, stored once.

Tools it gives your agents (5)

ToolWhat it does
tooltrust_list_rulesReturns the full catalog of security rules used by the ToolTrust scanner, including rule IDs, titles, and descriptions. Useful for understanding what the scanner checks for.
tooltrust_lookupLook up historical security risk grades for an MCP server from the public ToolTrust Directory. Accepts the kebab-case name of the server and returns its full JSON scan report, or 404 if not found.
tooltrust_scan_configReads the user's Claude Code MCP configuration and scans all configured servers in parallel. Searches for .mcp.json in the current directory, then ~/.claude.json as fallback.
tooltrust_scan_serverConnects to a live MCP server via standard input/output (stdio), parses its tools, and scans them for prompt injection, data exfiltration, and privilege escalation risks.
tooltrust_scanner_scanScan a list of AI agent tool definitions for security risks. Accepts an MCP tools/list JSON payload and returns a risk report with gateway policies (ALLOW, REQUIRE_APPROVAL, or BLOCK) for each tool.

Signals

GitHub stars
19
Forks
6
Last commit
Aug 2026
Weekly downloads
124
Tools captured
5