MCP Scanner
Dangerous tools, prompt leakage, permission escalation, and tool chaining risks across MCP server configs.
Upload MCP configs, agent settings, prompts, tool definitions, and RAG pipelines. Our ai scanner runs five targeted scanners to surface permission risks, dangerous tools, prompt leakage, SSRF, tool chaining, and data exposure — plus intent vs. reality gaps where agents are described as read-only but enable shell or filesystem tools.
Dangerous tools, prompt leakage, permission escalation, and tool chaining risks across MCP server configs.
Excessive permissions, unsafe tool access, and autonomous execution risks in agent settings.
Hidden secrets, system prompt leakage, and prompt injection vulnerabilities in prompt files.
Dangerous shell access, SSRF-capable tools, file deletion capabilities, and arbitrary code execution.
Sensitive documents indexed, PII exposure, and access control gaps in retrieval pipelines.
Download a PDF with findings grouped by scanner category, severity, and remediation guidance.
Scan via REST with your API key — same engines as the upload form.
Example request
curl -X POST "http://api.misconfigs.com/api/v1/ai?format=json&fail_on=critical,high" \ -H "X-API-Key: mc_your_key" \ -F "file=@sample/ai/mcp.json"
Upload MCP, agent, prompt, tool, or RAG configs — or zip them together
See it in action
Try the AI intent-gap demo — upload below to see reality gaps and suggested fixes.
Click a demo — we download the zip for you, then run the scan automatically. Keep this tab open; results appear below (usually 1–2 minutes).
One free demo per day — no account. Sign in free for more demos and your own uploads.
Drag & drop your AI configs here
MCP · agent · prompt · tool · RAG · .zip · max 10 MB
Automated scans only — not a penetration test, compliance audit, or professional security advice. Results may contain false positives or miss issues. You are responsible for validating findings before acting. Terms · Privacy
The optional scan assistant and Explain actions use Google Gemini (a third-party AI). Responses are generated automatically and may be inaccurate or incomplete — not security, legal, or professional advice. Chat sends finding details, scan summaries, and your messages to Google for processing. Do not include secrets you cannot afford to disclose. Official Terms (AI section) and Privacy Policy (AI section) are the source of truth, not assistant replies.
misconfigs is an MCP scanner for Model Context Protocol server configs (mcp.json), Cursor and Claude Desktop MCP settings, agent definitions, prompts, tool schemas, and RAG pipelines.
The AI security scanner finds dangerous tool exposure, shell access, SSRF-capable tools, prompt injection surfaces, and intent gaps where agents are labeled read-only but enable filesystem or network tools.