Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.
Scan MCP servers for prompt injection, data exfiltration, risky permissions, supply-chain threats, and privilege escalation before your agent blindly trusts them. First run downloads a ~10MB Go binary from GitHub Releases and caches it at . Subsequent runs use the cached binary with no download. Prompt injection and tool poisoning hidden in descriptions Excessive permissions such as , , , and…
Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Forge hat zu diesem Eintrag keinen Scan verzeichnet und hat daher keine Beobachtung seiner Tool-Oberfläche. Das ist das Fehlen eines Belegs, nicht der Beleg, dass er keine Tools offenlegt.
Scan MCP servers for prompt injection, data exfiltration, risky permissions, supply-chain threats, and privilege escalation before your agent blindly trusts them. First run downloads a ~10MB Go binary from GitHub Releases and caches it at . Subsequent runs use the cached binary with no download. Prompt injection and tool poisoning hidden in descriptions Excessive permissions such as , , , and Supply-chain CVEs and known compromised package versions Suspicious npm lifecycle scripts that execute…