MCTS audits MCP servers and tool manifests before your agent ever calls them. 30+ analyzers for tool-poisoning, prompt-injection, and credential-leak vectors. Local, fast, and assistant-agnostic.
Detects hidden instructions, deceptive descriptions, and behavior that diverges from a tool's declared schema.
Scans tool outputs and manifests for injected directives designed to hijack the agent's instructions.
Flags tools that read environment secrets, tokens, or keys and route them to unexpected destinations.
Run MCTS in pre-commit or CI. It returns a structured report and a non-zero exit code on any finding above your threshold, so poisoned tools never reach production agents.
scanning 14 tools · 30+ analyzers ✓ filesystem-mcp clean ✓ github-mcp clean ✗ notes-mcp tool-poisoning ↳ hidden directive in description ! mailer-mcp cred-leak (med) 2 findings · exit 1 · report.json
Open source, local-first, and built to slot straight into the pipeline you already run.