MCP SECURITY SCANNER

Scan your MCP servers before attackers do.

Orithos runs 124 offensive probes against your AI agent endpoint and its MCP tools — tool poisoning, prompt injection, cross-origin escalation, secret leakage — and returns ALLOW/DENY verdicts mapped to compliance frameworks. No agent instrumentation. Results in minutes.

PRIVATE BETA · 1,000 SCAN CREDITS / MONTH · NO CARD REQUIRED

What the 124 probes test

The full catalog is public — every payload, every expected behavior, every framework mapping. These are the categories and probe counts, verbatim from probe_catalog v1.1.0.

Injection & Prompt Attacks

The agent is tricked into executing attacker-controlled instructions.

  • Direct prompt injection3
  • Indirect / web-input injection7
  • Supply-chain & RAG poisoning5
  • Instruction hierarchy violation1
  • Goal hijacking1
  • Context-window snooping1

Tool & Permission Abuse

Legitimate tools used illegitimately — the core MCP risk.

  • Tool abuse chains5
  • Privilege escalation2
  • Undeclared MCP tools1
  • MCP description poisoning1
  • MCP resource exfiltration1
  • Access control bypass1

Data & Secret Leakage

What leaves the system that shouldn't.

  • Prompt leakage4
  • Secret disclosure1
  • Unauthorized exfiltration2
  • Training-data extraction1
  • Membership inference1
  • Audit traceability gaps1

Jailbreaks & Manipulation

Safety controls defeated by framing, encoding, or persistence.

  • Roleplay jailbreaks4
  • Encoding-based jailbreaks4
  • Hypothetical framing3
  • Chained jailbreaks3
  • Safety filter bypass1
  • Output / response manipulation7

Operational & Compliance

Availability, governance, and regulatory duties.

  • Resource exhaustion3
  • API abuse9
  • Overreliance on agent output5
  • Identity confusion3
  • Human oversight failures1
  • EU AI Act / GDPR / data governance7

MCP_DESCRIPTION_POISONING

Tool descriptions rewritten to steer the model — the tool lies about itself.

MCP_RESOURCE_EXFILTRATION

MCP resources read paths the agent should never touch.

MCP_UNDECLARED_TOOLS

Hidden tools not declared in the manifest, callable anyway.

The MCP security checklist

The four phases every agent deployment should pass — and what Orithos automates.

1 · Inventory

  • Every MCP server the agent can reach is listed — including dev and staging
  • Every tool, resource, and prompt template is declared in the manifest
  • No hidden/undeclared tools are callable at runtime
  • Tool descriptions match observed behavior (no description poisoning)

2 · Contain

  • Filesystem tools scoped to explicit allowlists — no wildcards
  • HTTP/browser tools blocked from internal ranges and metadata endpoints
  • Database tools read-only unless a write is explicitly required
  • Cross-tool escalation paths mapped (a tool whose output feeds another)

3 · Probe

  • Direct and indirect prompt injection tested against every tool entry point
  • Secret-exfiltration payloads attempted via every output channel
  • Jailbreak encodings (base64, unicode, chained) exercised
  • Resource exhaustion attempted under realistic limits

4 · Enforce

  • ALLOW/DENY verdicts per tool call — enforced, not just logged
  • Findings triaged and mapped to SOC 2 / HIPAA / EU AI Act controls
  • Re-scans scheduled after every agent or MCP server change
  • Evidence retained: request, response, verdict, policy version

124

offensive probes

40K+

checks per scan

30 CRITICAL

payload classes ready

15+

standards mapped

Orithos publishes its full probe catalog and a 14-hour public red-team report — see exactly what gets tested before you create an account. No demo-gated marketing.