Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.
Scan MCP servers for prompt injection, data exfiltration, risky permissions, supply-chain threats, and privilege escalation before your agent blindly trusts them. First run downloads a ~10MB Go binary from GitHub Releases and caches it at . Subsequent runs use the cached binary with no download. Prompt injection and tool poisoning hidden in descriptions Excessive permissions such as , , , and…
Inferido de los transportes que declara este listado (stdio). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Forge no tiene ningún análisis registrado de esta entrada, así que no tiene ninguna observación de su superficie de herramientas. Eso es ausencia de pruebas, no prueba de que no exponga ninguna herramienta.
Scan MCP servers for prompt injection, data exfiltration, risky permissions, supply-chain threats, and privilege escalation before your agent blindly trusts them. First run downloads a ~10MB Go binary from GitHub Releases and caches it at . Subsequent runs use the cached binary with no download. Prompt injection and tool poisoning hidden in descriptions Excessive permissions such as , , , and Supply-chain CVEs and known compromised package versions Suspicious npm lifecycle scripts that execute…