Powered by CCS fault taxonomy v2.5 โ 88 detection rules, 52 ZDI cases, 8 verified PoCs, 19 CVE-class vulnerabilities.
Install and run your first scan in under 30 seconds.
88 detection rules across 215 fault types. Here are the key categories:
Detect shell=True with user-controlled input, os.system calls, and eval/exec patterns.
CWE-78Unrestricted URL fetching from LLM output, internal IP access, and metadata endpoint leaks.
CWE-918Hardcoded API keys, tokens in source, env vars in logs, and secrets in config files.
CWE-200Unsanitized file paths, directory traversal in tool arguments, and symlink attacks.
CWE-22String-formatted queries, unsanitized ORM calls, and NoJS injection in document stores.
CWE-89Exception swallowing in auth checks, broad except clauses, and silent guardrail failures.
CWE-636Start free. Upgrade when you need more. Hard limits on free tier โ no surprises.
Install in seconds. Scan your first MCP config in under a minute.