The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the MCP Shield listing page.
A security scanner for MCP servers — detect backdoors, exfiltration, prompt injection, and supply chain risks before they reach your AI.
The MCP ecosystem is growing fast. Not every server on npm is safe. mcp-shield lets Claude audit any MCP server — local or from npm — before you trust it with your files, keys, and context.
| Category | Examples |
|---|---|
| Exfiltration | process.env sent over network, SSH key access, AWS credential reads |
| Code execution | eval(), new Function(), child_process.exec(), dynamic require() |
| Obfuscation | Base64 runtime decoding, hex-encoded payloads, char-code arrays |
| Sensitive file access | .env, id_rsa, browser cookies, ~/.gitconfig |
| Prompt injection | Hidden instructions, zero-width characters, role-switch attacks, jailbreak patterns |
| Supply chain | Package age, download count, maintainer count, CVEs in dependencies |
| Tool | What it does |
|---|---|
scan_package | Download an npm MCP package and scan it for malicious patterns |
scan_directory | Scan a local MCP server directory (cloned from GitHub, etc.) |
check_prompt_injection | Check tool descriptions or responses for hidden injections |
audit_supply_chain | Get trust score, CVEs, maintainer count, and age for any npm package |
Add to ~/.claude/claude_mcp_config.json:
Static analysis — scans JavaScript/TypeScript source files with a library of regex patterns covering 20+ attack signatures across 5 categories.
Supply chain audit — queries the npm registry for package metadata, then runs npm audit to surface known CVEs in the dependency tree.
Prompt injection detection — checks tool descriptions and responses for zero-width characters, instruction overrides, role-switch attacks, and other LLM-targeting techniques.
--ignore-scripts installation — when scanning npm packages, installs with --ignore-scripts so no malicious postinstall hooks run during analysis.
PRs welcome. Detection patterns live in src/patterns.ts — adding new signatures is a single object.
MIT