What would your MCP server leak today?
MCPGuard statically scans MCP servers, configs and agent skills for prompt injection, leaked credentials and over-broad permissions. Free, anonymous, no signup — results in seconds.
Paste an mcpServers JSON config (Claude Desktop / Cursor style) — parsed statically, nothing is executed.
Free: 3 scans per browser session per month. The scanner fetches
metadata only (initialize / tools/list) — it never
executes tool calls. This page posts to the local Floci API
(POST {API}/scan, GET {API}/reports/<id>) — dev
environment on magnus, no production deploy, no payments.
Scan report
Rule pack v0 — static analysis only (credentials, injection phrases, permission breadth, skill-file hygiene). Findings are hypotheses to review, not proof of compromise.