prompt-protection runs on your own machine — the client starts it, so there is no endpoint to ping. 575 installs a week from npm. Last commit 15 Sep 2026.
Scan prompts, tool definitions and model output for injection, and guard agent tool calls.
We read the source, 19 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
subprocess.run(["node", str(HERE / "normalize.mjs"), "--strings", str(inp), str(outp)], check=True)
'/wH//Pv9/AEABf8IAQAAAQEA/wMCAAD//woD/f8BAPz3Af8AAgD5/wAABAECAgD//wIAAAEAAAD+AAAA+gPp/wADAAD7AP/3AAD//P38/gD//wEE/wAA/vwUAQMD/wD0AAD+CAAABv4C+/8AAAIEAP//A/3/AvwAAAQBAQH8AAAB9AIEAAAAAADkAvP/AAQJAv8AAQH+/v//AQECAf3/+v8A/AABAAYDAAABAQEB/wH6/v/+/wH+AAMA/QH+/v8AAP8C+gEAAAMAAfQA/AAAA…
pattern: /(read|open|output|return|show|cat|print)\s+.{0,20}(\/etc\/passwd|\/etc\/shadow|\/etc\/hosts|\.env|secrets?\.json|credentials?\.json|config\.json|id_rsa)/,
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add prompt-protection -- npx -y prompt-protection
{
"mcpServers": {
"prompt-protection": {
"args": [
"-y",
"prompt-protection"
],
"command": "npx"
}
}
}
[mcp_servers.prompt-protection]
command = "npx"
args = ["-y", "prompt-protection"]
{
"mcpServers": {
"prompt-protection": {
"args": [
"-y",
"prompt-protection"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"prompt-protection": {
"args": [
"-y",
"prompt-protection"
],
"command": "npx"
}
}
}
Scan AI agents for tool-calling vulnerabilities: prompt leaks, hijacking, injections, and more.
Prompt-injection firewall for AI agents — scan untrusted text before LLM calls.
AI agent security: prompt injection detection, semantic memory, output scanning, prompt hardening
130+ QA & dev tools for AI agents: prompt injection, RAG testing, VLM eval, guardrails. Free.
Scan prompts for injection attacks, redact PII, and audit LLM SDK usage from any MCP client
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Security gateway for MCP agents: blocks prompt-injection-driven tool calls before they execute.
AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
Answers built from our own checks of this server.