Agent♥︎Age
Catalog

ToolTrust Scanner

Official

by AgentSafe-AI · Go

Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.

ToolTrust Scanner (MCP Server)

ToolTrust Scanner is a static security scanner for MCP tool definitions. It evaluates risk by checking for prompt injection, data exfiltration, and privilege escalation, producing trust grades (A–F) before an agent calls a tool. It can be run as an MCP server, a CLI check, or as part of a CI workflow.

🛠️ Key Features

  • Scans MCP servers for prompt injection
  • Checks for data exfiltration
  • Flags potential privilege escalation
  • Assigns trust grades (A–F) for tool definitions

🚀 Use Cases

  • Pre-call validation of MCP tools by generating trust grades
  • MCP-server-based integration into agent environments
  • CLI usage and CI checks for supply-chain and tool-definition security review

⚡ Developer Benefits

  • Standardizes review of MCP tool definitions via static analysis
  • Produces grade-based outcomes (A–F) to support go/no-go decisions

⚠️ Limitations

  • Described as a static security scanner for tool definitions; no runtime behavior testing is specified.

Topics

ai-securitygatewaygolangmcpmodel-context-protocolprompt-injectionsecurity-scanneragent-safetyai-security-toolmcp-servermcp-toolssupply-chain-security

Related servers

More in Security