OWASP MCP TOP 10 · CONTINUOUS SCANNING

Your agents trust MCP servers.
Should you?

Every MCP server you connect is remote code running inside your agent loop. MCPGuard audits them continuously — prompt injection surfaces, credential exposure, toxic tool flows — before your agent executes them.

5-min setup CI-native SOC2-ready reports
mcppguard scan — claude_desktop_config.json
the problem

MCP security is where web security was in 2005.

The protocol is fine. The ecosystem isn't. Anyone can publish a server; nothing verifies what it does after install. These are the findings we see in production configs every week.

MCP-01

Command injection args

Server spawn commands with unsanitized user input. One crafted tool call → arbitrary shell execution on your workstation.

MCP-02

Rug-pull updates

The server you audited last month shipped a new version that now exfiltrates env vars. Nothing re-checks it. We do — on every release.

MCP-03

Shadow credentials

API keys and tokens sitting in plaintext configs, committed to git, or visible to every tool in the session context.

MCP-04

Toxic tool combinations

A filesystem reader plus a web-fetcher plus a shell is a perfect data-exfiltration pipeline. Individually fine. Together: fatal.

MCP-05

Prompt injection surface

Tool descriptions and response bodies that quietly steer your agent toward unauthorized actions. We fingerprint the patterns.

MCP-06

No audit trail

Your SOC2 auditor asks what tools your agents called last quarter. You have no answer. We generate the evidence.

how it works

One command. Then it never sleeps.

Point MCPGuard at your agent configs (Claude Code, Claude Desktop, Cursor, custom stacks). It builds an inventory, static-scans every server, then keeps watching.

01

Inventory & static analysis

Parses every connected server, dependency, and permission scope. Flags OWASP MCP Top 10 findings with severity and exact file:line evidence.

02

CI/CD gate

GitHub Action that fails the build when a new MCP server or version introduces a critical finding. Shift-left for agent infrastructure.

03

Continuous monitoring

Re-audits on every upstream release. Slack alert the moment a trusted server starts asking for new permissions or env access.

04

Compliance reports

One-click SOC2 / ISO 27001 evidence packs: tool call audit logs, change history, exception registers. Auditors love us.

05

Deep scan — source-level audit

We download the server's npm package and tell you what it actually does: shells spawned, env vars read, sensitive paths touched, endpoints phoned, obfuscated payloads. File:line evidence.

06

Rug-pull watch

mcpguard watch snapshots every package version and alerts the moment an upstream release ships — re-audit before it executes. Run it from cron, CI, or your pre-commit hook.

pricing

Priced like a tool. Not like a breach.

Per team, unlimited servers. The free tier is a real scanner, not a demo — because we were your team six months ago.

🚀 LAUNCH WEEK — Lifetime Team license $199 one-time (first 50 teams, no subscription ever again). Buy lifetime — $199

SOLO

$0/mo
  • 1 seat · 5 servers
  • On-demand scans
  • CLI + findings report
  • Community support
Start free
MOST TEAMS

TEAM

$49/mo
  • 10 seats · unlimited servers
  • Continuous monitoring + alerts
  • CI/CD gate
  • Team dashboard & history
  • SOC2 evidence packs
Subscribe — $49/mo

ENTERPRISE

$199/mo
  • Unlimited seats
  • SSO / SCIM · audit log export
  • Custom policy rules
  • Private finding database
  • Priority support
Talk to us
early access

Get scanned before your agents get burned.

Join the early-access list. First 100 teams get the Team plan free for 6 months — and a founder who answers support tickets personally.

No spam. One launch email. 37 teams joined this week.