mcp-armor runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 4 Sep 2026.
Security sidecar for MCP servers: 11 read-only control-plane tools for prompt-injection checks.
We read the source, 20 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
"fullwidth_evasion" => &["sudo", "rm -rf", "curl", "wget"],
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
r"\.ssh/id_(rsa|ed25519|ecdsa)",
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch mcp-armor and you get told the day something new turns up.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Security scanner for MCP servers - detects tool poisoning and injection
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
MCP server security scanner: detects prompt injection, credential leaks, SSRF, tool poisoning.
Security gateway for MCP agents: blocks prompt-injection-driven tool calls before they execute.
Read-only portfolio tools, resources, and prompts for Fmind.
AI agent tools for Open Security Controls Assessment Language (OSCAL)
Free MCP server: 32 security & developer API tools -- WHOIS, DNS, CVE checks, IP reputation.
Answers built from our own checks of this server.