scan_mcp_server
ActiveTool of Tech Risk Enrichment
Security-audit a target MCP server for prompt-injection / tool-poisoning. Fetches the server's advertised tools and statically analyzes each for hidden instructions, data-exfiltration hints, dangerous capabilities, cross-tool shadowing, and invisible-unicode payloads (OWASP LLM01/LLM08). Returns findings + a 0-100 risk score + verdict (clear/review/block). Cost: $0.05 USDC per scan via x402.
Parameters schema
{
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"url"
],
"properties": {
"url": {
"type": "string",
"description": "Target MCP server endpoint URL to audit"
}
}
}No endpoints wrapped at confidence ≥ 0.70.
Parent server
Tech Risk Enrichment
1/7 registries