{
  "markdown": "# Agent Security MCP Server\n\nSecurity scanning, prompt injection detection, secret leak detection, and agent permission auditing for AI agent workflows. Built on the Model Context Protocol (MCP).\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `scan_mcp_config` | Scan MCP server configurations for security issues (dangerous commands, exposed secrets, network exposure, container misconfigs) |\n| `detect_prompt_injection` | Analyze text for prompt injection attempts across 7 attack categories with context-aware risk scoring |\n| `validate_scope_contract` | Check if agent actions comply with scope contracts (tool allowlists, file access, boundary constraints) |\n| `scan_secrets` | Detect leaked API keys, tokens, private keys, database URIs, and credentials in text or code |\n| `audit_agent_permissions` | Audit agent configurations against role-based expectations and flag principle of least privilege violations |\n| `generate_security_report` | Generate comprehensive security assessment reports with prioritized remediation plans |\n| `detect_tool_poisoning` | Analyze MCP tool definitions for hidden instructions that could manipulate agent behavior (OWASP Agentic Top 10) |\n\n## Resources\n\n| Resource | URI | Description |\n|----------|-----|-------------|\n| OWASP LLM Top 10 | `security://owasp-llm-top10` | OWASP Top 10 for LLM Applications (2025) |\n| MCP Security Checklist | `security://mcp-security-checklist` | Security checklist for MCP server deployments |\n\n## Installation\n\n```bash\ncd agent-security-mcp\nnpm install\n```\n\n## Usage\n\n### As a standalone server\n\n```bash\nnpm start\n```\n\n### In Claude Desktop / MCP client configuration\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-security\": {\n      \"command\": \"node\",\n      \"args\": [\"/path/to/agent-security-mcp/src/index.js\"]\n    }\n  }\n}\n```\n\n### With npx (after publishing)\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-security\": {\n      \"command\": \"npx\",\n      \"args\": [\"@asl-throne/agent-security-mcp\"]\n    }\n  }\n}\n```\n\n## Detection Coverage\n\n### Prompt Injection (7 categories, 20+ patterns)\n\n- **Instruction Override** -- \"ignore previous instructions\", \"disregard all rules\", \"new instructions:\"\n- **Identity Manipulation** -- \"you are now\", \"pretend you are\", \"act as\", DAN/jailbreak\n- **System Prompt Extraction** -- \"repeat your system prompt\", \"show your instructions\"\n- **Data Exfiltration** -- \"send this to\", \"post to webhook\", \"email everything to\"\n- **Delimiter Attacks** -- \\`\\`\\`system, [INST], <|im_start|>system, XML tag injection\n- **Encoded Injection** -- Base64 payloads, unicode zero-width characters, hex escapes\n- **Privilege Escalation** -- \"sudo mode\", \"disable safety\", \"bypass filters\"\n\n### Secret Detection (25+ patterns)\n\n- **AI Provider Keys** -- OpenAI (sk-*), Anthropic (sk-ant-*)\n- **Cloud Credentials** -- AWS (AKIA*), GCP (AIza*), Azure connection strings\n- **Source Control** -- GitHub PATs (ghp_*, github_pat_*), OAuth tokens (gho_*)\n- **Payment** -- Stripe live/test keys (sk_live_*, sk_test_*)\n- **Communication** -- Slack tokens/webhooks, Telegram bot tokens\n- **Database** -- PostgreSQL, MongoDB, MySQL, Redis connection URIs\n- **Cryptographic** -- RSA/EC/OpenSSH private keys, generic PEM blocks\n- **JWT** -- JSON Web Tokens\n- **Generic** -- api_key=, secret=, password=, .env file patterns\n\n### Permission Audit (6 role profiles)\n\n- **Researcher** -- Read + search + web only\n- **Analyst** -- Read + search only\n- **Developer** -- Read + write + execute\n- **Reviewer** -- Read only, no network\n- **Orchestrator** -- Read + write + task spawning\n- **Monitor** -- Read only, no network, no write\n\n## Pricing\n\n| Plan | Price | Servers | Features |\n|------|-------|---------|----------|\n| Free | $0 | 1 server | Single scan, basic report |\n| Starter | $49/month | 3 servers | Continuous scanning, weekly reports |\n| Pro | $199/month | 20 servers | Real-time alerts, CI/CD integration, Slack notifications |\n| Enterprise | $799/month | Unlimited | Custom policies, EU AI Act compliance reporting, SSO, dedicated support |\n\n## Requirements\n\n- Node.js >= 18.0.0\n- @modelcontextprotocol/sdk >= 1.12.0\n\n## License\n\nMIT\n",
  "bytes": 4117,
  "sha": "3101f23f9d288f4f92f43e418edc6e62317024428fd57c93214f7c9043cd668e",
  "repo_slug": "mdfifty50-boop/agent-security-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_mdfifty50_boop_agent_security_28137460/readme"
}