Scans MCP server packages and directories for malicious code, prompt injection, and supply chain risks.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ we're steadily working through the catalog.
๐ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by MCP Shield.
scan_packageDownload an npm MCP package and scan it for malicious patterns
scan_directoryScan a local MCP server directory (cloned from GitHub, etc.)
check_prompt_injectionCheck tool descriptions or responses for hidden injections
audit_supply_chainGet trust score, CVEs, maintainer count, and age for any npm package
A security scanner for MCP servers โ detect backdoors, exfiltration, prompt injection, and supply chain risks before they reach your AI.
The MCP ecosystem is growing fast. Not every server on npm is safe. mcp-shield lets Claude audit any MCP server โ local or from npm โ before you trust it with your files, keys, and context.
| Category | Examples |
|---|---|
| Exfiltration | process.env sent over network, SSH key access, AWS credential reads |
| Code execution | eval(), new Function(), child_process.exec(), dynamic require() |
| Obfuscation | Base64 runtime decoding, hex-encoded payloads, char-code arrays |
| Sensitive file access | .env, id_rsa, browser cookies, ~/.gitconfig |
| Prompt injection | Hidden instructions, zero-width characters, role-switch attacks, jailbreak patterns |
| Supply chain | Package age, download count, maintainer count, CVEs in dependencies |
| Tool | What it does |
|---|---|
scan_package | Download an npm MCP package and scan it for malicious patterns |
scan_directory | Scan a local MCP server directory (cloned from GitHub, etc.) |
check_prompt_injection | Check tool descriptions or responses for hidden injections |
audit_supply_chain | Get trust score, CVEs, maintainer count, and age for any npm package |
Add to ~/.claude/claude_mcp_config.json:
Static analysis โ scans JavaScript/TypeScript source files with a library of regex patterns covering 20+ attack signatures across 5 categories.
Supply chain audit โ queries the npm registry for package metadata, then runs npm audit to surface known CVEs in the dependency tree.
Prompt injection detection โ checks tool descriptions and responses for zero-width characters, instruction overrides, role-switch attacks, and other LLM-targeting techniques.
--ignore-scripts installation โ when scanning npm packages, installs with --ignore-scripts so no malicious postinstall hooks run during analysis.
PRs welcome. Detection patterns live in src/patterns.ts โ adding new signatures is a single object.
MIT
Factual signals from GitHub, npm, and our automated checks โ not a rating.
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/muhannad-hash-mcp-shield)<a href="https://allmcps.com/mcp/muhannad-hash-mcp-shield"><img src="https://allmcps.com/api/badge/muhannad-hash-mcp-shield?style=directory" alt="MCP Shield on AllMCPs" /></a>