Skip to content
🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
Pro · AI Security

Malicious MCP Server Scanner

The moment your agent lists an MCP server’s tools, the tool descriptions enter the model’s context — so a poisoned description is code execution against your agent. Paste a server’s tool list and screen it for tool-poisoning, exfiltration, secret access, arbitrary execution, over-broad scope and rug-pull behaviour before you ever connect it.

Checking your plan…
TL;DR

What this tool is

  • Paste an MCP server’s tools/list response (or manifest) and get it screened for malicious patterns before you connect an agent to it.
  • Detects tool-poisoning (instructions hidden in tool descriptions), data-exfiltration shape, secret/credential access, arbitrary execution, over-broad scope, rug-pull / remote-update risk, hidden unicode, and concealment requests.
  • Returns a per-tool finding list with severity and the exact snippet that triggered it, plus a connect/do-not-connect verdict.
  • Runs entirely in your browser — the manifest is never uploaded. Pro tool, included with any PlayCISO paid plan.

Frequently asked questions

What is the Malicious MCP Server Scanner?

A Pro tool that statically screens a Model Context Protocol (MCP) server’s advertised tools for the patterns used to attack agents. You paste the server’s tools/list JSON (or a manifest with a "tools" array) and it flags tool-poisoning, exfiltration-shaped tools, secret access, arbitrary execution, over-broad scopes, rug-pull / remote-update behaviour, hidden unicode and concealment instructions — each with the offending snippet.

How is this different from your MCP Server Risk tool?

MCP Server Risk scores a server’s overall posture and reputation. This scanner is the adversarial complement: it reads the actual tool definitions and hunts for the specific tricks malicious or compromised MCP servers use — most importantly tool-poisoning, where instructions to the model are smuggled inside a tool’s description so the agent is hijacked the moment the tool is listed.

Does it prove a server is safe or malicious?

No — it is a heuristic triage aid, deliberately noisy. A clean result means no known patterns matched, not that the server is trustworthy; a finding means something deserves human review before you connect. Always also check the publisher, the requested scopes, and whether the server fetches anything remote after approval.

Is it free?

No. This is a Pro tool included with any PlayCISO paid plan. The page explains exactly what it checks; the interactive scanner unlocks with a subscription.

Malicious MCP Server Scanner — Pro AI Security Tool · PlayCISO