How it works
Four steps, about half a minute, nothing installed on your machine.
Opens a real MCP session over Streamable HTTP, with SSE as a fallback.
Reads every tool, prompt and resource. Flags hidden instructions, bloated descriptions and dangerous capabilities.
An AI agent tries read-only tools with harmless inputs. A code-level gate blocks anything destructive.
Every finding is scored and you get a grade from A to F with the evidence behind it.
Recent scans
Every grade comes from a real run on this instance. Click one to open its report.