ClaudeSuperPower
T

ToolTrust Scanner

MCP Server

Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.

Install

claude mcp add tooltrust-scanner -- npx -y tooltrust-mcp

What is ToolTrust Scanner?

Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.

Trust

83/100 · Excellent

2 factors scored below maximum

Documentation

README · ~6 min read

ToolTrust

ToolTrust Scanner

Static security scanner for MCP tool definitions
Trust grades (A–F) before your agent calls a tool — run as an MCP server, CLI, or CI check.

CI Security Go Report Card License: MIT GitHub stars


Every MCP tool your agent calls is an attack surface — prompt injection, data exfiltration, privilege escalation, supply-chain backdoors. ToolTrust scans tool definitions before your agent trusts them and assigns a trust grade (A–F) so you know the risk. ToolTrust is an MCP Server and a CLI/CI tool — not a host, gateway, or runtime proxy. Coverage is expanding beyond today’s MCP-focused workflows; skills and additional agent tool formats are on the roadmap.

Browse the live ToolTrust Directory — trust grades and scan-backed reports before you install.

ToolTrust Directory UI

MCP demo: run a full config scan from your agent.

ToolTrust MCP demo

Scan your setup in 30 seconds

Add ToolTrust as an MCP server and let your agent audit its own tools (stdio transport — no network listener; your host launches it as a subprocess):

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just mcp servers.