Every MCP server you connect is remote code running inside your agent loop. MCPGuard audits them continuously — prompt injection surfaces, credential exposure, toxic tool flows — before your agent executes them.
The protocol is fine. The ecosystem isn't. Anyone can publish a server; nothing verifies what it does after install. These are the findings we see in production configs every week.
Server spawn commands with unsanitized user input. One crafted tool call → arbitrary shell execution on your workstation.
The server you audited last month shipped a new version that now exfiltrates env vars. Nothing re-checks it. We do — on every release.
API keys and tokens sitting in plaintext configs, committed to git, or visible to every tool in the session context.
A filesystem reader plus a web-fetcher plus a shell is a perfect data-exfiltration pipeline. Individually fine. Together: fatal.
Tool descriptions and response bodies that quietly steer your agent toward unauthorized actions. We fingerprint the patterns.
Your SOC2 auditor asks what tools your agents called last quarter. You have no answer. We generate the evidence.
Point MCPGuard at your agent configs (Claude Code, Claude Desktop, Cursor, custom stacks). It builds an inventory, static-scans every server, then keeps watching.
Parses every connected server, dependency, and permission scope. Flags OWASP MCP Top 10 findings with severity and exact file:line evidence.
GitHub Action that fails the build when a new MCP server or version introduces a critical finding. Shift-left for agent infrastructure.
Re-audits on every upstream release. Slack alert the moment a trusted server starts asking for new permissions or env access.
One-click SOC2 / ISO 27001 evidence packs: tool call audit logs, change history, exception registers. Auditors love us.
We download the server's npm package and tell you what it actually does: shells spawned, env vars read, sensitive paths touched, endpoints phoned, obfuscated payloads. File:line evidence.
mcpguard watch snapshots every package version and alerts the moment an upstream release ships — re-audit before it executes. Run it from cron, CI, or your pre-commit hook.
Per team, unlimited servers. The free tier is a real scanner, not a demo — because we were your team six months ago.
Join the early-access list. First 100 teams get the Team plan free for 6 months — and a founder who answers support tickets personally.
No spam. One launch email. 37 teams joined this week.