NewFree MCP security scan — no signup

Instant MCPSecurity Scan

Is your MCP server safe? Paste a URL and get a real posture report in seconds — tool poisoning, prompt injection, secret leaks, exfiltration and cross-layer attack chains. No signup.

Try:— or paste your own URL / config above

No registration Secrets never stored Free · static · results in seconds

OWASP AgenticMCP Top 10MITRE ATLASOWASP LLM Top 10OWASP API

Findings mapped to the standards security teams trust

What it detects

Tool poisoning

Hidden instructions, deceptive naming, encoded payloads in tool defs

Prompt injection

Direct, indirect & RAG-retrieval injection surfaces

Supply chain

Typosquats, rug-pulls, unpinned/unsigned servers, drift

Transport & auth

Weak TLS, missing auth, SSRF, stdio command injection

Secrets exposure

Hardcoded creds, connection strings, private keys

Over-privilege

Destructive capability, excessive tool access, confused deputy

Data exfiltration

Covert channels, markdown-image exfil, unrestricted egress

Memory & RAG

Knowledge-base poisoning, memory injection, time-bombs

Identity

Non-expiring tokens, shared identity, weak binding

Multi-agent (A2A)

Trust inheritance, transitive privilege escalation

LLM config

Weak guardrails, unbounded consumption, unsafe output

Cross-layer chains

How minor findings connect into a critical exfil path

Why it matters

MCP servers hand your agent tools that can read files, call APIs and run commands. A single poisoned tool description, a leaked key, or a covert exfil channel turns a helpful agent into a breach. Real incidents already show tool-poisoning and prompt-injection chains in the wild — most configs are never reviewed.

How it works

  1. 1. Paste a URL or config — scanned in memory, secrets never stored.
  2. 2. 63 static detectors run and stream findings live with exact evidence.
  3. 3. Get a posture score + prioritized findings. Register for full evidence; upgrade for deep behavioral scans.
Prefer local / private scans? Use the CLI — nothing leaves your machine.
npx sensoit scan ./mcp.json
See pricing