Mcpshield runs on your own machine — the client starts it, so there is no endpoint to ping. 42 installs a week from npm. Last commit 13 Apr 2026.
Security scanner for MCP servers - detects tool poisoning and injection
Today is the operative word: we check Mcpshield every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add mcpshield -- npx -y mcpshield-cli
{
"mcpServers": {
"mcpshield": {
"args": [
"-y",
"mcpshield-cli"
],
"command": "npx"
}
}
}
[mcp_servers.mcpshield]
command = "npx"
args = ["-y", "mcpshield-cli"]
{
"mcpServers": {
"mcpshield": {
"args": [
"-y",
"mcpshield-cli"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"mcpshield": {
"args": [
"-y",
"mcpshield-cli"
],
"command": "npx"
}
}
}
MCP server security scanner: detects prompt injection, credential leaks, SSRF, tool poisoning.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
MCP security scanner: detect tool poisoning, prompt injection & rug-pulls - 10 OWASP heuristics.
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
Security scanning and threat detection for AI agents
Security scanner and runtime proxy for MCP servers.
Answers built from our own checks of this server.