Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.
ToolTrust Scanner (MCP Server)
ToolTrust Scanner is a static security scanner for MCP tool definitions. It evaluates risk by checking for prompt injection, data exfiltration, and privilege escalation, producing trust grades (A–F) before an agent calls a tool. It can be run as an MCP server, a CLI check, or as part of a CI workflow.
🛠️ Key Features
Scans MCP servers for prompt injection
Checks for data exfiltration
Flags potential privilege escalation
Assigns trust grades (A–F) for tool definitions
🚀 Use Cases
Pre-call validation of MCP tools by generating trust grades
MCP-server-based integration into agent environments
CLI usage and CI checks for supply-chain and tool-definition security review
⚡ Developer Benefits
Standardizes review of MCP tool definitions via static analysis
Produces grade-based outcomes (A–F) to support go/no-go decisions
⚠️ Limitations
Described as a static security scanner for tool definitions; no runtime behavior testing is specified.
Static security scanner for MCP tool definitions
Trust grades (A–F) before your agent calls a tool — run as an MCP server, CLI, or CI check.
Every MCP tool your agent calls is an attack surface — prompt injection, data exfiltration, privilege escalation, supply-chain backdoors. ToolTrust scans tool definitions before your agent trusts them and assigns a trust grade (A–F) so you know the risk. ToolTrust is an MCP Server and a CLI/CI tool — not a host, gateway, or runtime proxy. Coverage is expanding beyond today’s MCP-focused workflows; skills and additional agent tool formats are on the roadmap.
It reads your MCP config, connects to each server in parallel, scans every tool, and returns a risk report with grades and enforcement decisions — all in seconds.
The public ToolTrust Directory holds current grades and aggregates as scanning scales. One published research pass illustrates the shape of the problem — 207 MCP servers, 3,235 tools — not an exhaustive count of everything we scan today:
Metric
Count
MCP servers in cohort
207
Individual tools analyzed
3,235
Total security findings
3,613
Servers with at least one finding
145 (70%)
Servers with a clean Grade A
22 (10%)
Servers with arbitrary code execution
16
Only 10% of servers in that cohort had a clean Grade A. See tooltrust.dev for up-to-date directory-wide results (and use this table only as a labeled snapshot).
🔍 What it catches
ToolTrust runs 16 static tool-definition rules in this repo (AS-001–AS-011, AS-013–AS-017) plus 2 source-scan rules for embedded MCP implementations (AS-018, AS-019). AS-012 (tool drift) is evaluated in the ToolTrust Directory when new scan results are compared to previous runs.
DoS Resilience — No rate-limit, timeout, or retry config on network/exec tools
🔄 AS‑012
High
Rug-Pull — Tool set changed between scans of the same version without a version bump (directory pipeline only)
👥 AS‑013
High/Medium
Tool Shadowing — Duplicate or near-duplicate tool name hijacks calls intended for a trusted tool
ℹ️ AS‑014
Info
Dependency Inventory Unavailable — MCP server exposed neither metadata.dependencies nor a repo_url, so supply-chain coverage is limited and must be treated as incomplete
⚠️ AS‑015
Medium/High
Suspicious NPM Lifecycle Script — npm dependency publishes preinstall / postinstall / similar install-time scripts; severity rises for remote-fetch or inline-execution patterns
🚨 AS‑016
Critical
Suspicious NPM IOC Dependency — published npm metadata or install-time scripts reference a known malicious IOC package, domain, URL, or reviewed script pattern such as plain-crypto-js, even if the top-level package name is new
⚠️ AS‑017
Medium
Suspicious Data Exfiltration Description — tool description explicitly suggests sending user data, content, or conversation history to external / remote endpoints, without classifying it as prompt injection
ℹ️ AS‑018
Info
Embedded MCP Server Detected — source-level MCP SDK usage was found, but tools could not be enumerated from a manifest or live handshake, so manual review is still required
🔓 AS‑019
High
Unauthenticated MCP Route Exposure — embedded MCP HTTP routes expose the same handler without equivalent authentication middleware
For deployment, use the install paths in Install or the workflow example in CI / GitHub Actions. For vulnerability reporting and disclosure policy, see docs/SECURITY.md.
Scan-before-install gate
Never add an untrusted MCP server to your config again:
bash
# Scans the server, then auto-installs if Grade A/B, prompts on C/D, blocks on F
tooltrust-scanner gate @modelcontextprotocol/server-memory -- /tmp
# Replace `claude mcp add` with a scanned installalias mcp-add='tooltrust-scanner gate'
Full gate options and pre-commit hook setup: docs/USAGE.md
Add a trust badge to your project
If your MCP server passes ToolTrust, let people know:
Supply-chain alert: ToolTrust detects and blocks confirmed compromised packages including LiteLLM v1.82.7/8 (TeamPCP backdoor), Trivy v0.69.4–v0.69.6, and Langflow < 1.9.0. If you encounter a Grade F with rule AS-008, remove the package immediately and rotate all credentials.