MCP / Tool Registry Scanner
Is your MCP server safe for an agent to trust?
An MCP tool's description is untrusted text your agent reads before it decides to call the tool. A malicious or compromised registry hides prompt-injection, exfiltration lures, auto-invoke bait, and privilege-overreach claims right there. Paste your tool list and AgentSmack flags the risky ones — deterministically, with the exact phrase and why it's dangerous.
What we flag
Injection (“ignore previous instructions”), exfiltration (“send the full context to…”), auto-invoke bait (“always call this first”), guardrail-disable, privilege overreach, and supply-chain (fetch-and-execute, impersonation).
Deterministic + private
Same tools → same report (no LLM in the loop). Your tool list is analyzed in-request and never stored. CORS-open at /api/v1/mcp-scan.