MCP Security Framework
Project · AI security
Sandboxes any MCP server in Docker and runs 14 detectors before an AI agent is allowed near it.
- 14 detectors
- 60+ servers tested
- 30–90 s per target
- My role Designer and builder
- Tested 60+ real MCP servers
- Output HTML · TXT · SARIF for GitHub
- Evidence JSON / JSONL logs
MCP is a new security boundary
Once an LLM can call tools, the MCP server becomes the enforcement point between untrusted instructions and real systems. Web scanners do not understand MCP resources, prompts, tool descriptions or stdio/SSE transports, so the framework speaks MCP natively.
Covers injection, data exposure, access control, enumeration and tool-level abuse.
Maps every finding to CWE, OWASP LLM / API Top 10 and CVSS.
Point it at anything; it builds the sandbox
The sandboxing stage (AMSAW) infers source type, language, transport, entry point and dependencies, then launches the server in an isolated Docker runtime. GitHub repos, npm packages, local folders and live URLs all work without hand-written Docker commands.
Offence, with a leash
Detectors never touch a target directly. A SafeAdapter enforces request budgets, rate limits, timeouts, scope and evidence redaction, so active testing stays controlled even inside a CI pipeline.
Prompt and indirect injection, code execution, credential exposure, excessive permissions, tool poisoning, shadowing, rug-pull, enumeration.
Each detector returns status, confidence, evidence, remediation and standards mapping.