{"uid":"cap_ks_Ppuzw2yGV54rotPrnx","slug":"agentstools-mcp-security-scanner-d29333a7","name":"AgentsTools MCP Security Scanner","description":"Static security scan of an MCP manifest or tool list. Detects tool poisoning, hidden unicode instructions, prompt injection, data-exfiltration directives, dangerous capabilities, tool shadowing and post-approval rug-pull drift. Returns a 0-100 risk score, category, per-tool findings and content hashes. Security indicators, not a guarantee.","url":"https://api.agentstools.dev/mcp/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"tools":{"type":"array","items":{"type":"object"},"description":"Alternatively, a list of tool objects (name, description, inputSchema)"},"manifest":{"type":"object","description":"MCP manifest object (with a tools list) or a single tool object"},"known_hashes":{"type":"object","description":"Optional map of tool name to a previously pinned tool_hash, to detect rug-pull drift"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_sRzhs4eHDKx5ugMsOf0Fa","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a static security scan of an MCP manifest or tool list, returning a 0-100 risk score and per-tool findings covering prompt injection, tool poisoning, hidden unicode, data exfiltration, and rug-pull drift.","exampleAgentPrompt":"Scan this MCP manifest for security threats — check for prompt injection, hidden unicode, tool poisoning, and data exfiltration directives, and give me a risk score and per-tool findings.","exampleUseCases":[{"title":"Pre-deployment MCP audit","prompt":"Before I deploy this MCP server, scan the tool manifest for any prompt injection, hidden unicode, or data exfiltration risks and give me the risk score so I know if it's safe to use."},{"title":"Rug-pull drift detection","prompt":"I have the hashes from my tools last week — can you scan my current MCP manifest against those known hashes to see if any tool definitions have silently changed since I approved them?"},{"title":"Third-party tool vetting","prompt":"I'm about to add this third-party tool list to my agent — scan it for tool poisoning, dangerous capabilities, and tool shadowing before I allow my agent to use it."}],"resultDescription":"Returns a 0-100 risk score, a risk category label, per-tool security findings (covering prompt injection, hidden unicode, tool poisoning, data exfiltration directives, dangerous capabilities, tool shadowing, and rug-pull drift), and content hashes for each tool. Results are security indicators, not a guarantee of safety.","failureModes":["Missing required 'input' field returns validation error","Invalid body type or HTTP method enum value causes 400","Malformed or non-object manifest/tools array results in parse error","Empty tools list may return no findings but still consumes the $0.01 fee","Network timeout if manifest is extremely large","known_hashes with mismatched keys silently skips drift detection for unmatched tools"],"whenToPreferThis":"Choose this endpoint when you need a fast, automated static security analysis of MCP tool manifests or tool lists before deploying or integrating third-party agent tools. It is specifically designed for MCP/agent-tool security scenarios including rug-pull drift detection via hash pinning, which generic code scanners or LLM-based reviews do not provide. Prefer it over manual review when you need a quantified, reproducible 0-100 risk score with per-tool breakdown.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:57:00.877Z","isFirstParty":false}