Paste an MCP server URL. gate connects, lists its tools, and grades it A–F — prompt injection, hidden instructions, over-broad permissions, and provenance. A hosted MCP inspector with a security scan built in.
Connects to the server, completes the handshake, and lists every tool it exposes — a hosted MCP inspector, no install.
Language in a tool description written to hijack your AI — overriding its rules or hiding actions from you.
Invisible or bidirectional Unicode characters used to smuggle instructions past a human skim.
References to secrets, credentials, env vars, or sending your data somewhere else.
Tools that run arbitrary code, shell, or SQL — capabilities worth gating.
Whether the server is on gate's verified list, so you have a third-party signal.
A Claude pass over every tool for manipulation the pattern checks miss.
We connect to the server without authentication and read its public tool list, so servers that require OAuth can’t be scanned here — connect those inside gate. We don’t store the server URL or the report.