MCP / Tool Registry Scanner

Is your MCP server safe for an agent to trust?

An MCP tool's description is untrusted text your agent reads before it decides to call the tool. A malicious or compromised registry hides prompt-injection, exfiltration lures, auto-invoke bait, and privilege-overreach claims right there. Paste your tool list and AgentSmack flags the risky ones — deterministically, with the exact phrase and why it's dangerous.

What we flag

Injection (“ignore previous instructions”), exfiltration (“send the full context to…”), auto-invoke bait (“always call this first”), guardrail-disable, privilege overreach, and supply-chain (fetch-and-execute, impersonation).

Deterministic + private

Same tools → same report (no LLM in the loop). Your tool list is analyzed in-request and never stored. CORS-open at /api/v1/mcp-scan.