mcpbeat Sign in

Cloakcheck MCP Server

by vercel-cloakcheck-wheat Your server? Claim it
answering

Cloakcheck is answering right now. Last checked 12 min ago. It exposes 1 tools.

Scan a page for hidden prompt-injection payloads targeting AI agents.

Uptime history 5 days of history
5 days agonow
100.0%
Uptime 24h
91 of 91 checks
1
Tools
read from the server
239 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check Cloakcheck every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 12 min ago.

run in your terminal
claude mcp add cloakcheck --transport http https://cloakcheck-wheat.vercel.app/api/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "cloakcheck": {
      "url": "https://cloakcheck-wheat.vercel.app/api/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.cloakcheck]
url = "https://cloakcheck-wheat.vercel.app/api/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "cloakcheck": {
      "url": "https://cloakcheck-wheat.vercel.app/api/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "cloakcheck": {
      "url": "https://cloakcheck-wheat.vercel.app/api/mcp"
    }
  }
}

Available tools 1

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

page
check_page_for_injection
Scan a single web page for content planted to hijack an AI agent reading it -- invisible unicode (zero-width chars, the unicode 'tag' block used for steganographic prompt injection), CSS-hidden instruction text, and instruction-shaped language in alt/title/aria-label attributes a human would never read. Does NOT judge whether visible body text is safe -- only content hidden from normal human reading flow is flagged, so a page that legitimately discusses prompt injection won't false-positive on itself. Call this before an autonomous shopping/browsing agent acts on a page's content (add to cart, follow instructions found on the page, etc).

Endpoints

URLTransportStateLatencyChecked
https://cloakcheck-wheat.vercel.app/api/mcp streamable-http answering 206 ms 12 min ago

Alternatives to Cloakcheck

same job, measured the same way
Agentglass
by agentglass

Scan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth.

1 tools answering
Injectshield
by bch1212

Prompt-injection firewall for AI agents — scan untrusted text before LLM calls.

24 installs/wk local only
Email Guard MCP
by mlawsonking

Email safety for AI agents: scan inbound for prompt-injection/phishing + outbound for secret leaks.

67 installs/wk local only
1Claw Vault
by 1clawai

HSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.

472 installs/wk local only
I
Agent Security Scanner
by mikehzp

Scan AI agents for tool-calling vulnerabilities: prompt leaks, hijacking, injections, and more.

113 installs/wk local only
Agent Safe
by wowcool

Email safety MCP server. Detects phishing, prompt injection, CEO fraud for AI agents.

answering
IA-QA — 130+ QA & Dev Tools for AI Agents
by jcjamet

130+ QA & dev tools for AI agents: prompt injection, RAG testing, VLM eval, guardrails. Free.

152 tools answering
Agent Immune
by denial-web

AI agent security: prompt injection detection, semantic memory, output scanning, prompt hardening

85 installs/wk local only

Cloakcheck — questions

Answers built from our own checks of this server.

What can Cloakcheck do?
It exposes 1 tools, read directly from the server on our last check. Among them: check_page_for_injection. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Cloakcheck working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 239 ms. The bar chart above shows every period we have measured.
How do I connect Cloakcheck?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Cloakcheck need an API key?
No. Cloakcheck completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 1 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Cloakcheck?
It answers our handshake in 239 ms on average, which is faster than 59% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.