MCP Hub
Back to servers

tooltrust-mcp

Scans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.

glama
Stars
3
Updated
Mar 27, 2026
Validated
Mar 28, 2026

ToolTrust Scanner

CI Security GitHub stars Go Report Card License: MIT

Scan MCP servers for prompt injection, data exfiltration, and privilege escalation before your AI agent blindly trusts them.

🚨 Urgent Security Update (March 24, 2026) ToolTrust now detects and blocks the LiteLLM / TeamPCP supply chain exploit. If you are adding MCP servers that rely on litellm (v1.82.7/8), ToolTrust will trigger a CRITICAL Grade F warning and block installation to protect your SSH/AWS keys.

ToolTrust Scanner demo

🤖 Let your AI agent scan its own tools

Add ToolTrust as an MCP server in your .mcp.json and your agent can audit every tool it has access to:

{
  "mcpServers": {
    "tooltrust": {
      "command": "npx",
      "args": ["-y", "tooltrust-mcp"]
    }
  }
}

Then ask your agent to run tooltrust_scan_config — it reads your MCP config and scans all servers in parallel.

ToolDescription
tooltrust_scan_configScan all servers in your .mcp.json or ~/.claude.json in parallel
tooltrust_scan_serverLaunch and scan a specific MCP server
tooltrust_scanner_scanScan a JSON blob of tool definitions
tooltrust_lookupLook up a server's trust grade from the ToolTrust Directory
tooltrust_list_rulesList all 12 security rules with IDs and descriptions

💻 CLI

# Install
curl -sfL https://raw.githubusercontent.com/AgentSafe-AI/tooltrust-scanner/main/install.sh | bash

# Scan any MCP server
tooltrust-scanner scan --server "npx -y @modelcontextprotocol/server-filesystem /tmp"

# Scan-then-install: gate checks a server before adding it to your config
tooltrust-scanner gate @modelcontextprotocol/server-memory -- /tmp
Other install methods
# Go install
go install github.com/AgentSafe-AI/tooltrust-scanner/cmd/tooltrust-scanner@latest

# Homebrew
brew install AgentSafe-AI/tap/tooltrust-scanner

# Specific version
curl -sfL https://raw.githubusercontent.com/AgentSafe-AI/tooltrust-scanner/main/install.sh | VERSION=vX.Y.Z bash

🚪 Gate: scan-before-install

tooltrust-scanner gate scans an MCP server before installing it. Grade A/B auto-installs, C/D prompts for confirmation, F blocks entirely.

# Scan and install if safe (writes .mcp.json)
tooltrust-scanner gate @modelcontextprotocol/server-memory -- /tmp

# Dry run — scan only, don't install
tooltrust-scanner gate --dry-run @modelcontextprotocol/server-filesystem -- /tmp

# Block anything below grade B
tooltrust-scanner gate --block-on B @some/package

# Install to user config (~/.claude.json) instead of project
tooltrust-scanner gate --scope user @some/package

# Override the server name in config
tooltrust-scanner gate --name my-server @some/package

# Force install regardless of grade (with warning)
tooltrust-scanner gate --force @some/package
FlagDefaultDescription
--namederived from packageServer name in config
--dry-runfalseScan only, don't install
--block-onFMinimum grade that blocks: F, D, C, B
--scopeprojectproject (.mcp.json) or user (~/.claude.json)
--forcefalseBypass grade check
--deep-scanfalseEnable AI-based semantic analysis
--rules-dirbuilt-inCustom YAML rules directory

Exit codes: 0 = installed (or dry-run), 1 = blocked by policy, 2 = error.

🔗 Pre-Hook Integration

Shell alias

Replace claude mcp add with tooltrust-scanner gate so every install is scanned first:

alias mcp-add='tooltrust-scanner gate'
# mcp-add @modelcontextprotocol/server-memory -- /tmp

Git pre-commit hook

If .mcp.json is checked into your repo, scan it on every commit:

# .git/hooks/pre-commit
#!/bin/sh
if git diff --cached --name-only | grep -q '\.mcp\.json'; then
  tooltrust-scanner scan --input .mcp.json --fail-on block || exit 1
fi

🔍 What it catches

IDSeverityDetects
AS-001CriticalPrompt poisoning / injection in tool descriptions
AS-002High/LowExcessive permissions (exec, network, db, fs)
AS-003HighScope mismatch (name contradicts permissions)
AS-004High/CritSupply chain CVEs via OSV
AS-005HighPrivilege escalation (admin scopes, sudo)
AS-006CriticalArbitrary code execution
AS-007InfoMissing description or schema
AS-008CriticalKnown-compromised package versions — offline blacklist (TeamPCP/litellm, trivy, langflow) with zero latency
AS-009MediumTyposquatting (edit-distance impersonation)
AS-010MediumInsecure secret handling in params
AS-011LowMissing rate-limits or timeouts
AS-013High/MedTool shadowing (duplicate name hijacking)

🤝 GitHub Actions

- name: Audit MCP Server
  uses: AgentSafe-AI/tooltrust-scanner@main
  with:
    server: "npx -y @modelcontextprotocol/server-filesystem /tmp"
    fail-on: "approval"

Developer guide · Contributing · Changelog · Security · License: MIT © 2026 AgentSafe-AI

Feedback

Found a false positive? A tool that should be flagged but isn't?

Report false positiveA tool was flagged but shouldn't be
Report missed detectionA tool should have been flagged
File a bugSomething is broken

Reviews

No reviews yet

Sign in to write a review