AIShield Security Scanner is answering right now. Last checked 1 min ago. 32 installs a week from npm. It exposes 10 tools. Last commit 22 Sep 2026.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 28 August 2026. No other catalogue keeps this.
We read the source, 9 h ago · tools taken from the live server · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
(r"\brm\s+(-rf|-r)\b", "rm -rf — 可删除文件/目录"),
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
proc = subprocess.run(
asset_path = os.path.join(BASE, "static", rel)
svg.innerHTML=html;
"answer": "AIShield's sandbox-hardening rules detect a mounted docker.sock, the --privileged flag, host network, PID, and IPC namespaces, cap_add set to ALL, seccomp set to unconfined, --user 0, and Kubernetes hostPath mounts.",
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
- name: Create or update digest Issue
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch AIShield Security Scanner and you get told the day something new turns up.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 1 min ago.
claude mcp add aishield --transport http https://aishield.tools/api/v1/mcp
{
"mcpServers": {
"aishield": {
"url": "https://aishield.tools/api/v1/mcp"
}
}
}
[mcp_servers.aishield]
url = "https://aishield.tools/api/v1/mcp"
{
"mcpServers": {
"aishield": {
"url": "https://aishield.tools/api/v1/mcp"
}
}
}
{
"mcpServers": {
"aishield": {
"url": "https://aishield.tools/api/v1/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
aishield_banned_words
aishield_digest
aishield_guardrail
aishield_handshake
aishield_prompt_check
aishield_rug_pull
aishield_scan
aishield_vertical_risk
agent_quick_scan
agent_register
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://aishield.tools/api/v1/mcp | streamable-http | answering | 868 ms | 1 min ago |
Security scanner for MCP servers - detects tool poisoning and injection
MCP server security scanner: detects prompt injection, credential leaks, SSRF, tool poisoning.
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
MCP security scanner: detect tool poisoning, prompt injection & rug-pulls - 10 OWASP heuristics.
Security sidecar for MCP servers: 11 read-only control-plane tools for prompt-injection checks.
Security scanner for MCP servers. SSRF, path traversal, injection, auth, secrets. Grade A-F.
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Answers built from our own checks of this server.