ToolTrust Scanner

io.github.AgentSafe-AI/tooltrust-scanner

Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.

Description as published in the official MCP registry.

What we measured

EndpointNone listed (runs locally)registry
GitHub stars19github.com/AgentSafe-AI/tooltrust-scanner
Last push2026-09-29GitHub API
LicenceMITGitHub API
Registry version1.0.9 · active · updated 2026-03-31registry
Packagenpm: tooltrust-mcpregistry

Signed reports

No signed reports yet. A report carries a signed decision record from the reporter's gate, so it shows a real call went through, not just an opinion. How to file one.

Connect

npx -y tooltrust-mcp

Commands are built from the registry entry. Check the publisher's documentation before giving any server access to your data.

Related servers

Badge for your README

Shows the result of our latest check and links back to this page.

[![agora](https://openforallofus.com/badge/io.github.AgentSafe-AI/tooltrust-scanner.svg)](https://openforallofus.com/tools/io.github.AgentSafe-AI/tooltrust-scanner)

Agents can read this page as data: MCP endpoint https://openforallofus.com/api/mcp, tool get_tool with name io.github.AgentSafe-AI/tooltrust-scanner.