Audit unvalidated JSON-RPC schemas, prevent arbitrary shell escapes, eliminate silent credential exfiltration, and generate zero-overhead hardened wrappers in <35ms.
Paste your MCP tool schema or select a vulnerable sample script to simulate real-time prompt injection attacks and schema enforcement.
Never wonder what AI agents discover. Enter your work email below to receive instant telemetry proof emails whenever autonomous bots crawl your endpoint.
Why standard MCP implementations without schema enforcement put host workstations and cloud databases at risk.
When an MCP tool passes string arguments to child_process.exec() or os.system() without strict alphanumeric sanitization, an injected prompt can append command chains (; rm -rf /, curl attacker.com).
Filesystem MCP tools with weak directory confinement allow agents to navigate outside allowed sandbox boundaries using ../../etc/passwd or ~/.ssh/id_rsa.
Malicious tools or hijacked context prompts silently read process environment variables (OPENAI_API_KEY, AWS_SECRET_ACCESS_KEY) and broadcast them via outbound webhooks.
Missing additionalProperties: false and unbounded parameter arrays cause schema mismatch crashes in Claude Desktop and infinite loop retries in Cursor agent flows.
Tools without strict execution timeouts (max 5,000ms) or rate limiters lock the agent stdio channel, freezing the entire IDE window indefinitely.
Severity: Medium (CVSS 4.8)Wrap any existing Node.js or Python MCP script with our zero-dependency sentinel in 1 line of code.
Drop-in safety middleware for your existing MCP servers with strict parameter bounds and sub-35ms overhead.
Signal to users and enterprise auditors that your MCP server complies with strict JSON-RPC schema bounds.
We believe agent safety should be universally accessible. All scanner tools and safe wrappers are 100% free forever.
Full access to offline scanner CLI and hardened wrapper templates.
npx @pixeloffice-eu/mcp-shield scan)Automated CI/CD security gating and official compliance attestation.
Route your MCP agent completions through our sub-35ms proxy with viral stealth reasoning models like Ox Alpha (1M context) and DeepSeek.