Is your MCP server safe? Paste a URL and get a real posture report in seconds — tool poisoning, prompt injection, secret leaks, exfiltration and cross-layer attack chains. No signup.
No registration Secrets never stored Free · static · results in seconds
Findings mapped to the standards security teams trust
Hidden instructions, deceptive naming, encoded payloads in tool defs
Direct, indirect & RAG-retrieval injection surfaces
Typosquats, rug-pulls, unpinned/unsigned servers, drift
Weak TLS, missing auth, SSRF, stdio command injection
Hardcoded creds, connection strings, private keys
Destructive capability, excessive tool access, confused deputy
Covert channels, markdown-image exfil, unrestricted egress
Knowledge-base poisoning, memory injection, time-bombs
Non-expiring tokens, shared identity, weak binding
Trust inheritance, transitive privilege escalation
Weak guardrails, unbounded consumption, unsafe output
How minor findings connect into a critical exfil path
MCP servers hand your agent tools that can read files, call APIs and run commands. A single poisoned tool description, a leaked key, or a covert exfil channel turns a helpful agent into a breach. Real incidents already show tool-poisoning and prompt-injection chains in the wild — most configs are never reviewed.
npx sensoit scan ./mcp.json