{"uid":"cap_K1DVDRE21WFd2GUjC4uMh","slug":"payai-mcp-security-scanner-b2004ad2","name":"PayAI MCP Security Scanner","description":"Static security scan of an MCP manifest or tool list. Detects tool poisoning, hidden unicode instructions, prompt injection, data-exfiltration directives, dangerous capabilities, tool shadowing and post-approval rug-pull drift. Returns a 0-100 risk score, category, per-tool findings and content hashes. Security indicators, not a guarantee.","url":"https://payai.agentstools.dev/mcp/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"tools":{"type":"array","items":{"type":"object"},"description":"Alternatively, a list of tool objects (name, description, inputSchema)"},"manifest":{"type":"object","description":"MCP manifest object (with a tools list) or a single tool object"},"known_hashes":{"type":"object","description":"Optional map of tool name to a previously pinned tool_hash, to detect rug-pull drift"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NGPbD8GxQsOL_ncuZzrMx","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Statically scans an MCP manifest or tool list for security threats including tool poisoning, prompt injection, hidden unicode, data-exfiltration directives, tool shadowing, and rug-pull drift, returning a 0-100 risk score with per-tool findings.","exampleAgentPrompt":"Can you run a security scan on this MCP manifest and tell me the risk score and what specific threats were found — I want to know if there's any prompt injection, tool shadowing, or hidden unicode before I connect it to my agent?","exampleUseCases":[{"title":"Pre-connection MCP server vetting","prompt":"Before I let my agent connect to this third-party MCP server, scan its manifest for me and give me the risk score and any findings — especially check for tool poisoning or data exfiltration directives."},{"title":"Post-update drift detection","prompt":"I approved this MCP tool list last week and now it's been updated — can you scan the new version and tell me if anything changed that looks like a rug-pull or new security risk?"},{"title":"Agent fleet tool audit","prompt":"Here's the tool manifest for all the tools my agent fleet uses — run a security scan and flag any tools with hidden unicode instructions, prompt injection, or dangerous capabilities, along with the overall risk score."}],"resultDescription":"Returns a 0-100 risk score, a risk category label, per-tool findings listing detected threats (tool poisoning, hidden unicode, prompt injection, data-exfiltration, dangerous capabilities, tool shadowing, rug-pull drift), and SHA content hashes for each tool. Results are security indicators and not a guarantee of safety.","failureModes":["Malformed or unparseable MCP manifest returns validation error","Empty tool list may return minimal findings with no meaningful score","Very large manifests may time out or be truncated","Obfuscated or encoded payloads may evade static detection","Novel attack patterns not in the detection ruleset may be missed"],"whenToPreferThis":"Use this endpoint when you need to statically audit an MCP manifest or tool list before connecting it to an AI agent, or when verifying that a previously approved manifest hasn't drifted. It is purpose-built for MCP-specific threats like tool shadowing and rug-pull drift that generic security scanners don't cover. Prefer it over manual review or generic linters when you want a structured risk score and per-tool findings with content hashes for change tracking.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:34:03.134Z","isFirstParty":false}