{"uid":"cap_NIqUmMx9QfIvcXVMGm6lz","slug":"grey-ridge-signals-mcp-security-scanner-x402-9d00fbee","name":"Grey Ridge Signals — MCP Security Scanner (x402)","description":"Agent-native pay-per-call data on Base (USDC via x402). No API keys, no signup. Discovery: /.well-known/x402","url":"https://x402-data-api.sigrunner.workers.dev/scan/mcp","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"properties":{"type":"string"}}},"responseSchema":{"type":"json","example":{"target":"https://example.com/mcp","verdict":"review","findings":[{"rule":"tool-poisoning:hidden-instructions","tool":"read_file","detail":"…","evidence":"…","severity":"critical"}],"risk_score":40,"risk_summary":"1 issue across 3 tools, 1 CRITICAL (tool-poisoning). Risk 40/100.","tools_scanned":3}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_701cT43l-HcdqicBfbOd1","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans an MCP server URL for security vulnerabilities including tool-poisoning and hidden instructions, returning a risk score and categorized findings","exampleAgentPrompt":"Can you scan https://example.com/mcp for security issues and tell me if any of its tools have hidden instructions or poisoning risks before I connect to it?","exampleUseCases":[{"title":"Pre-connection MCP server audit","prompt":"Before I add this MCP server at https://internal-tools.mycompany.com/mcp to my agent, can you scan it for tool-poisoning or hidden instructions and give me a risk score?"},{"title":"Detect prompt injection in third-party tools","prompt":"I found a public MCP server at https://some-public-mcp.io/mcp — can you check if any of its tools contain hidden malicious instructions or try to hijack my agent?"},{"title":"Security review of custom MCP build","prompt":"We just built an MCP server at https://dev.myapp.com/mcp — can you run a security scan on it and flag any rule violations or critical findings before we ship it?"}],"resultDescription":"Returns a JSON object with: the scanned target URL, a verdict (e.g. 'review' or 'pass'), an array of findings each with rule name, affected tool, detail, evidence, and severity (critical/high/medium/low), an overall risk_score (0–100), a human-readable risk_summary, and the count of tools_scanned.","failureModes":["Target URL is unreachable or returns non-MCP responses — scan may fail or return empty findings","Invalid or malformed target URL results in an error response","MCP server requires authentication that the scanner cannot satisfy, limiting tool discovery","x402 payment failure if USDC balance is insufficient or Base network is congested","Rate limiting if the same target is scanned repeatedly in quick succession"],"whenToPreferThis":"Use this endpoint when you need to programmatically verify the safety of an MCP server before connecting an AI agent to it — especially to detect tool-poisoning, hidden prompt injection, or malicious instructions embedded in tool definitions. Prefer it over manual inspection when you need a structured risk score and machine-readable findings for automated pipelines. It requires no API key and charges $0.10 USDC per scan via x402 on Base.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-16T06:38:58.198Z","isFirstParty":false}