Free tool · no login

Is that MCP server safe to connect?

Paste any MCP server URL and get an instant security report — prompt injection, hidden instructions, over-broad permissions, and provenance. The same scan gate runs before it connects a server.

Try:
What it checks

Six checks on every tool

Prompt injection

Language in a tool description written to hijack your AI — overriding its rules or hiding actions from you.

Hidden instructions

Invisible or bidirectional Unicode characters used to smuggle instructions past a human skim.

Data-exfiltration hints

References to secrets, credentials, env vars, or sending your data somewhere else.

Over-broad permissions

Tools that run arbitrary code, shell, or SQL — capabilities worth gating.

Provenance

Whether the server is on gate's verified list, so you have a third-party signal.

AI review

A Claude pass over every tool for manipulation the pattern checks miss.

We connect to the server without authentication and read its public tool list, so servers that require OAuth can’t be scanned here — connect those inside gate. We don’t store the server URL or the report.