In April 2026, security researchers disclosed a critical RCE vulnerability in Anthropic's Model Context Protocol — affecting 150 million SDK downloads and 200,000+ vulnerable production servers. Anthropic confirmed the behavior is by design and stated that sanitization is the developer's responsibility. We took that seriously.
A free open-source scanner that catches MCP security issues at the schema and configuration layer, and a commercial runtime that watches every live tool call in production — with the audit trail your auditors actually accept.
Static analysis of any MCP tool manifest or server config. Detects tool poisoning, prompt injection, hidden-Unicode steganography, dangerous schemas, embedded secrets, unsafe stdio launch patterns, and insecure HTTP transports. One command, JSON or text output, exits non-zero on critical findings — drop it directly into CI.
Sits inline on production MCP traffic. Enforces policy in real time. Logs every tool call to a tamper-evident audit trail. Pauses high-risk actions for human approval. Slack and PagerDuty alerts on suspicious activity. Free tier for solo developers, paid tiers for teams.
One-click audit reports for SOC 2, ISO 42001, and India's DPDP Act. Maps every agent action to the controls your auditors care about. Built for Indian SaaS exporters and global mid-market.
The scanner ships with five real security checks across two manifest shapes — the tool surface (what your agent sees) and the server surface (how your agent connects). Every finding is actionable, every detail tells you what to fix.
Static checks read the blueprints. Live-probe sends an actual auditor: it spawns the MCP server (or connects over HTTPS), calls initialize + tools/list, and runs every tool check on the response your agent will actually see.
Stdio and HTTP transports both supported. Stdlib-only client — no new runtime dependencies, no hidden network calls, no surprises.
The open-source scanner is yours to use today. Drop your email and we'll let you know when the Runtime alpha opens — typically a 2–3 week wait.
No spam. No retargeting pixels. Unsubscribe with one click.