mcpbeat Sign in

mcp-armor MCP Server

local only

mcp-armor runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 4 Sep 2026.

Security sidecar for MCP servers: 11 read-only control-plane tools for prompt-injection checks.

Installs / week
not published
1
Stars
0 open issues
4 Sep 2026
Last commit
from GitHub
MIT
License
Rust

What the code does

We read the source, 20 h ago · rules 3dff92dd89df

Evidence

Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.

Deletes files or strips permissions src/scanner/aho.rs:63
        "fullwidth_evasion" => &["sudo", "rm -rf", "curl", "wget"],
Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

            r"\.ssh/id_(rsa|ed25519|ecdsa)",

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

We found things in this code

Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch mcp-armor and you get told the day something new turns up.

Three servers free · no card

Alternatives to mcp-armor

same job, measured the same way
AIShield Security Scanner
by lm203688

Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

46 installs/wk 9 tools local only
Mcpshield
by mcpshield-dev

Security scanner for MCP servers - detects tool poisoning and injection

42 installs/wk local only
Mund — MCP Security Scanner
by tyox-all

Scan for prompt injection, secrets, PII, and vet MCP servers before installation

48 installs/wk local only
C
MCP Safeguard
by cognivators

MCP server security scanner: detects prompt injection, credential leaks, SSRF, tool poisoning.

125 installs/wk local only
Tripwire
by bonesdefi

Security gateway for MCP agents: blocks prompt-injection-driven tool calls before they execute.

35 installs/wk local only
Fmind AI Security Architect Portfolio
by fmind

Read-only portfolio tools, resources, and prompts for Fmind.

9 tools answering
MCP Server for OSCAL
by awslabs

AI agent tools for Open Security Controls Assessment Language (OSCAL)

156 installs/wk local only
Presend MCP Server
by presendapp

Free MCP server: 32 security & developer API tools -- WHOIS, DNS, CVE checks, IP reputation.

37 tools answering

mcp-armor — questions

Answers built from our own checks of this server.

Why is there no uptime for mcp-armor?
mcp-armor runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone.
Is mcp-armor open source?
Yes — it is published under the MIT licence, written in Rust and 1 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.