{"uid":"cap_Xqyp8JnnZYR5rXVgkfO28","slug":"mcp-manifest-security-scanner-ad98589d","name":"MCP Manifest Security Scanner","description":"Statically analyse a Model Context Protocol (MCP) server manifest for security risks. Tool descriptions enter the model context, a prime prompt-injection vector. Deterministic and offline (inline manifest). Flags dangerous capabilities (command/code execution, filesystem, credential and network access), injection patterns, hidden unicode and unconstrained parameters. Returns severity-ranked findings and a 0-100 score.","url":"https://mcpscan.openverbs.com/v1/scan","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object","properties":{"manifest":{"oneOf":[{"type":"object"},{"type":"array"}],"description":"The MCP manifest to scan: either an object (with a `tools` array, optionally `prompts`/`resources`) or a bare array of tool definitions. Each tool may have `name`, `description` and `inputSchema`."}},"additionalProperties":false},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_AbVBq3hf257L3c0QGR2jf","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans an MCP (Model Context Protocol) manifest for security risks, analyzing tool definitions, prompts, and resources for vulnerabilities or malicious patterns","exampleAgentPrompt":"Can you scan this MCP manifest for any security risks? It has a tools array with definitions for file access and shell execution — I want to know if anything looks dangerous before I deploy it.","exampleUseCases":[{"title":"Pre-deployment MCP server audit","prompt":"Before I publish my MCP server, can you scan its manifest for security risks? Here's the full manifest JSON with all my tool definitions including their descriptions and input schemas."},{"title":"Third-party MCP trust assessment","prompt":"I found an MCP server I want to connect my agent to — can you scan its manifest and tell me if any of the tools look malicious or have suspicious permissions?"},{"title":"CI pipeline MCP security gate","prompt":"Run a security scan on this MCP manifest from our latest build — flag any tools whose descriptions or schemas could enable prompt injection or unauthorized access."}],"resultDescription":"Returns a structured security report identifying risks found within the MCP manifest, including flagged tools, descriptions of detected vulnerabilities or suspicious patterns, and overall risk assessment of the manifest's tool definitions, prompts, and resources.","failureModes":["Missing required 'manifest' field in body returns validation error","Malformed manifest JSON that doesn't match expected object or array structure causes parse failure","Empty tools array may return no findings rather than an error","Very large manifests may time out or hit payload limits","Invalid bodyType enum value causes request rejection"],"whenToPreferThis":"Choose this endpoint when you need to specifically analyze MCP (Model Context Protocol) manifests for security vulnerabilities before deploying or connecting to an MCP server. It is purpose-built for MCP manifest structure including tools, prompts, and resources — prefer it over generic code scanners or JSON validators when the concern is AI agent tool safety and MCP-specific risk patterns like prompt injection in tool descriptions or overly permissive inputSchemas.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:36:53.762Z","isFirstParty":false}