Shadowgate MCP is answering right now. Last checked 11 min ago. Last commit 13 May 2026.
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
We read the source, 3 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
re.compile(r"(?:~|\$HOME|/home/[^\s]+|/Users/[^\s]+)?/\.ssh/(?:id_rsa|id_ed25519|id_ecdsa|config)\b|\\.ssh\\(?:id_rsa|id_ed25519|id_ecdsa|config)\b", LINE_FLAGS),
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 11 min ago.
claude mcp add shadowgate-mcp --transport http https://shadowgate-mcp.mcp.xpay.sh/mcp
{
"mcpServers": {
"shadowgate-mcp": {
"url": "https://shadowgate-mcp.mcp.xpay.sh/mcp"
}
}
}
[mcp_servers.shadowgate-mcp]
url = "https://shadowgate-mcp.mcp.xpay.sh/mcp"
{
"mcpServers": {
"shadowgate-mcp": {
"url": "https://shadowgate-mcp.mcp.xpay.sh/mcp"
}
}
}
{
"mcpServers": {
"shadowgate-mcp": {
"url": "https://shadowgate-mcp.mcp.xpay.sh/mcp"
}
}
}
This endpoint answered with an authorization challenge. The server is running, but it did not say what kind of credentials it expects.
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://shadowgate-mcp.mcp.xpay.sh/mcp | streamable-http | needs auth | 235 ms | 11 min ago |
AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
Multi-agent LLM security layer detecting prompt injection and jailbreaks.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Security scanning and threat detection for AI agents
Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
Multi-layer security scanner for MCP servers and agent skills (injection, exfiltration)
Answers built from our own checks of this server.