Detection rules
Every rule, with a demo you can run.
All 54 rules. Pick one to see a file that triggers it, the part that matters, and the result the scanner produces. The results are generated by running the real scanner, not written by hand.
The interactive demos need JavaScript. Here's every rule in the meantime.
Agent safety
- Prompt injection payload — Instructions aimed at the agent, hidden in text the agent is going to read anyway.
- Description doesn't match capability — A tool that describes itself as read-only while its parameters say otherwise.
- Invisible Unicode — Characters that render as nothing but still reach the model.
- Loose parameter schema — A high-risk input, like a URL or file path, that accepts absolutely anything.
- Concealed instruction — A command hidden in part of a file that rendered output never shows.
- Schema injection — An instruction hidden inside a parameter's description, one level below the tool's own.
- Unicode tag smuggling — Text written in Unicode Tag characters, which render as nothing at all.
- Tool shadowing — A tool that gives instructions about how a different tool should behave.
- Permission escalation request — Asks the person, not the machine, to lower a defence.
- Markdown image beacon — A markdown image whose address carries data out when the reply is displayed.
- Forged tool result — Text shaped like the output of a tool that never ran.
- Memory poisoning — Writes instructions into a file the agent reads at the start of every session.
- Deferred trigger — Behaves normally at first, then does something else later.
- Agent chain injection — An instruction addressed to the next agent in a chain, not to the user.
- Confused deputy — A tool with no special permissions directing the agent to use one that has them.
- System prompt extraction — Asks the agent to reveal its own instructions and tools.
- Conversation history access — Asks for the conversation history without its description giving a reason.
- Instruction in an error message — An instruction hidden in an error, where it's read at the moment nobody looks closely.
Exfiltration
- Exfiltration pattern — A tool that handles secrets and can also send data out.
- Webhook sink — A hard-coded address whose only purpose is to collect whatever is sent to it.
- DNS exfiltration — Data encoded into the names of domain lookups.
- Toxic capability flow — One tool that reads private data and can also publish somewhere outside.
- Network call in an "offline" tool — Says it never uses the network. Uses the network.
Credentials
- Hardcoded secret — A credential written directly into a file.
- Credential store access — Reads a file whose whole purpose is storing credentials.
- Cloud metadata access — Asks the cloud host for the credentials it hands to anything that asks.
- Shell history access — Reads the record of commands typed into a terminal.
- Credential in MCP config — A live token pasted into an MCP config file.
- Secret written to logs — A credential printed somewhere it will be kept far too long.
- OAuth misconfiguration — OAuth set up in a way that removes the protection it was added for.
Supply chain
- Untrusted external install — Setup instructions telling you to download something and run it.
- Unpinned MCP server — A server that can become different software without you doing anything.
- Known-vulnerable MCP server — A pinned version with a published security advisory.
- MCP package impersonation — A package name one character away from the one you meant.
- Install script hook — A command that runs from the internet the moment the package is installed.
- Dependency confusion — A public package named like one of your private ones.
- Vulnerable dependency — A declared dependency inside a published advisory's affected range.
- Missing provenance — A download that's installed without checking it's the genuine file.
- Homoglyph tool name — Two tool names that look identical on screen but aren't the same text.
- Duplicate tool name — The same tool name declared in two different files.
- Shadow MCP server — MCP servers your agent can use that your project's config doesn't declare.
- Toolset mutation — A tool you've seen before, now delivered from a different file and changed.
- Manifest drift — A tool you already reviewed, quietly changed afterwards.
Execution
- Excessive permissions — A tool that asks for far more access than its job could possibly need.
- Dynamic execution — Code assembled at run time from something the agent was handed.
- Opaque payload — Something bundled with a skill that no one can read — here, a program disguised as an ordinary file.
- MCP auto-approve — An MCP server configured to run every tool without asking.
- Over-broad MCP launch command — A launch command that hands the server more than it needs.
- MCP STDIO injection surface — A server on MCP's STDIO transport, where configuration values become a command the host runs.
- Persistence mechanism — Writes itself somewhere that survives a restart.
- Sandbox escape — References a way out of the container it runs in.
- String reassembly — Builds a dangerous word out of fragments so a search for it comes up empty.
- Command injection surface — A shell command built by pasting in a value supplied at run time.
- Permissive CORS — An HTTP server that lets any website call it.
OWASP MCP Top 10
Coverage across all ten categories.
Every rule maps to at least one category in the OWASP MCP Top 10, which is still in beta. Some rules cover more than one category, so the counts add up to more than the number of rules. Lack of audit and telemetry has one rule, and should: logging is a problem a scanner can point at, not solve.
| Category | Name | Rules | Relative coverage |
|---|---|---|---|
| MCP01 | Token Mismanagement & Secret Exposure | 7 | |
| MCP02 | Privilege Escalation via Scope Creep | 7 | |
| MCP03 | Tool Poisoning | 13 | |
| MCP04 | Software Supply Chain Attacks & Dependency Tampering | 13 | |
| MCP05 | Command Injection & Execution | 8 | |
| MCP06 | Intent Flow Subversion | 10 | |
| MCP07 | Insufficient Authentication & Authorization | 3 | |
| MCP08 | Lack of Audit and Telemetry | 1 | |
| MCP09 | Shadow MCP Servers | 1 | |
| MCP10 | Context Injection & Over-Sharing | 9 |
Run every rule on your own files.
The free plan includes all 54 rules and 20 scans a month.