# MCP Tool Schema Scanner

Paste your MCP server's tools/list response and see which lines of each tool schema allow path traversal, SSRF, or injection. Three annotated examples included. Runs in your browser; nothing is uploaded.

<div class="acp-container" style="max-width:860px;padding-top:72px;padding-bottom:80px;">

  <!-- Hero -->
  <div style="text-align:center;margin-bottom:48px;">
    <div style="display:inline-block;background:rgba(220,38,38,0.08);border:1px solid rgba(220,38,38,0.2);color:#dc2626;border-radius:20px;font-size:13px;font-weight:600;padding:5px 14px;margin-bottom:16px;"><a href="/blog/mcp-input-validation-attack-surface/" style="color:inherit;text-decoration:none;">2,432 of 8,216 MCP servers expose high-risk inputs with zero validation &rarr;</a></div>
    <h1 class="acp-hero-h1" style="font-size:2.4rem;margin-bottom:12px;color:var(--color-text-primary);">Is your MCP server secure?</h1>
    <p style="color:var(--color-text-secondary);font-size:1.1rem;max-width:580px;margin:0 auto;line-height:1.6;">
      Click an example to see exactly which lines of a tool schema create real vulnerabilities — and which ones prevent them.
    </p>
  </div>

  <!-- Three example cards (no grades) -->
  <div id="example-cards" style="margin-bottom:32px;">

    <button type="button" class="scan-example-btn" data-example="dangerous" style="all:unset;cursor:pointer;padding:20px;border-radius:var(--radius-lg);border:2px solid rgba(220,38,38,0.2);background:rgba(220,38,38,0.03);text-align:center;transition:border-color 150ms ease, box-shadow 150ms ease;">
      <div style="font-weight:800;font-size:17px;color:#dc2626;margin-bottom:4px;">Dangerous</div>
      <div style="font-size:13px;color:var(--color-text-secondary);line-height:1.4;">Raw file paths, SQL queries, shell commands. What most servers ship.</div>
    </button>

    <button type="button" class="scan-example-btn" data-example="risky" style="all:unset;cursor:pointer;padding:20px;border-radius:var(--radius-lg);border:2px solid rgba(202,138,4,0.2);background:rgba(202,138,4,0.03);text-align:center;transition:border-color 150ms ease, box-shadow 150ms ease;">
      <div style="font-weight:800;font-size:17px;color:#ca8a04;margin-bottom:4px;">Risky</div>
      <div style="font-size:13px;color:var(--color-text-secondary);line-height:1.4;">Some constraints, but key gaps remain. Common in production today.</div>
    </button>

    <button type="button" class="scan-example-btn" data-example="secure" style="all:unset;cursor:pointer;padding:20px;border-radius:var(--radius-lg);border:2px solid rgba(14,164,114,0.2);background:rgba(14,164,114,0.03);text-align:center;transition:border-color 150ms ease, box-shadow 150ms ease;">
      <div style="font-weight:800;font-size:17px;color:#0ea472;margin-bottom:4px;">Secure</div>
      <div style="font-size:13px;color:var(--color-text-secondary);line-height:1.4;">Constrained schemas, scoped inputs, clear descriptions. The gold standard.</div>
    </button>

  </div>

  <!-- Annotated code viewer (hidden until interaction) -->
  <div id="scan-code" style="display:none;"></div>

  <!-- Results (hidden until interaction) -->
  <div id="scan-results"></div>

  <!-- Divider -->
  <div style="margin:48px 0 36px;border-top:1px solid var(--color-border);"></div>

  <!-- Check your own server -->
  <div style="margin-bottom:48px;">
    <h2 class="acp-section-title" style="font-size:1.4rem;margin-bottom:8px;">Check your own server</h2>
    <p style="color:var(--color-text-secondary);font-size:15px;margin-bottom:16px;line-height:1.6;">
      Paste the <code>tools</code> array from your MCP server's <code>tools/list</code> response.
      <span style="color:var(--color-text-muted);font-size:13px;"> — 100% client-side, nothing leaves your browser.</span>
    </p>
    <form id="scan-form">
      <textarea
        id="scan-input"
        rows="10"
        placeholder='Paste your tools/list JSON here — the full response or just the "tools" array.'
        style="width:100%;padding:14px;background:var(--color-surface);border:1px solid var(--color-border);border-radius:var(--radius-md);color:var(--color-text-primary);font-family:var(--acp-font-mono);font-size:13px;line-height:1.5;resize:vertical;box-sizing:border-box;"
      ></textarea>
      <button type="submit" class="acp-btn acp-btn-primary" style="margin-top:12px;width:100%;padding:13px;font-size:15px;justify-content:center;">
        Scan for vulnerabilities
      </button>
    </form>
  </div>

  <!-- SEO content -->
  <div style="margin-bottom:48px;">
    <h2 class="acp-section-title" style="font-size:1.4rem;">What MCP security vulnerabilities look like</h2>
    <p style="color:var(--color-text-secondary);font-size:15px;line-height:1.7;margin-bottom:20px;">
      MCP servers expose tools that AI agents call autonomously. Every tool parameter is an attack surface — if the schema doesn't constrain it, the agent (or an attacker manipulating the agent) can exploit it.
    </p>
    <div class="scan-vuln-grid" style="display:grid;grid-template-columns:1fr 1fr;gap:16px;">
      <div style="padding:20px;border:1px solid var(--color-border);border-radius:var(--radius-lg);border-left:3px solid #dc2626;">
        <div style="font-size:12px;font-weight:700;text-transform:uppercase;letter-spacing:0.05em;color:#dc2626;margin-bottom:6px;">Path Traversal</div>
        <p style="font-size:14px;color:var(--color-text-secondary);line-height:1.5;margin:0;">A <code>path</code> parameter with no <code>pattern</code> constraint lets an agent read <code>../../etc/passwd</code> or overwrite system files.</p>
      </div>
      <div style="padding:20px;border:1px solid var(--color-border);border-radius:var(--radius-lg);border-left:3px solid #dc2626;">
        <div style="font-size:12px;font-weight:700;text-transform:uppercase;letter-spacing:0.05em;color:#dc2626;margin-bottom:6px;">SSRF</div>
        <p style="font-size:14px;color:var(--color-text-secondary);line-height:1.5;margin:0;">A <code>url</code> parameter without validation can target <code>http://169.254.169.254</code> (cloud metadata) or internal services.</p>
      </div>
      <div style="padding:20px;border:1px solid var(--color-border);border-radius:var(--radius-lg);border-left:3px solid #ea580c;">
        <div style="font-size:12px;font-weight:700;text-transform:uppercase;letter-spacing:0.05em;color:#ea580c;margin-bottom:6px;">Injection</div>
        <p style="font-size:14px;color:var(--color-text-secondary);line-height:1.5;margin:0;">Parameters named <code>query</code> or <code>command</code> that accept arbitrary strings are injection vectors. Use enums and parameterized queries.</p>
      </div>
      <div style="padding:20px;border:1px solid var(--color-border);border-radius:var(--radius-lg);border-left:3px solid #ea580c;">
        <div style="font-size:12px;font-weight:700;text-transform:uppercase;letter-spacing:0.05em;color:#ea580c;margin-bottom:6px;">Destructive Ops</div>
        <p style="font-size:14px;color:var(--color-text-secondary);line-height:1.5;margin:0;">Tools named <code>delete</code> or <code>drop</code> without authorization controls let any agent permanently erase data.</p>
      </div>
    </div>
  </div>

  <!-- How to get tools/list -->
  <div style="margin-bottom:48px;">
    <h2 class="acp-section-title" style="font-size:1.4rem;margin-bottom:12px;">How to get your tools/list response</h2>
    <div style="color:var(--color-text-secondary);font-size:14px;line-height:1.8;">
      <p><strong style="color:var(--color-text-primary);">curl</strong> (Streamable HTTP servers)</p>
      <pre style="padding:14px;background:#1e293b;border-radius:var(--radius-md);overflow-x:auto;margin-bottom:20px;font-size:13px;color:#e2e8f0;"><code>curl -s -X POST https://your-mcp-server/endpoint \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' \
  | jq '.result.tools'</code></pre>
      <p><strong style="color:var(--color-text-primary);">MCP Inspector</strong> — connect to any server, click "List Tools", copy the JSON.</p>
      <p><strong style="color:var(--color-text-primary);">Client logs</strong> — Claude Desktop, Cursor, and Cline all log <code>tools/list</code> responses.</p>
    </div>
  </div>

  <!-- CTA -->
  <div style="padding:32px;background:linear-gradient(135deg, rgba(91,91,214,0.06), rgba(8,145,178,0.04));border:1px solid rgba(91,91,214,0.2);border-radius:var(--radius-lg);">
    <h3 style="font-size:1.15rem;font-weight:700;color:var(--color-text-primary);margin:0 0 8px;">Fix the schema. Then control the call.</h3>
    <p style="color:var(--color-text-secondary);font-size:14px;line-height:1.6;margin:0 0 16px;">
      A constrained schema limits what a tool accepts. ACP limits what the agent is allowed to call: a hook in the agent harness sends every tool call, MCP or built-in, to the gateway before it runs. The gateway records it, applies your rules per tool and per agent tier, and returns allow, flag, ask, or deny. No server code changes. One command installs it for Claude Code, Cursor, Codex, and OpenClaw:
    </p>
    <pre style="margin:0 0 16px;padding:12px 14px;background:#0f172a;border-radius:var(--radius-md);overflow-x:auto;font-size:13px;"><code style="color:#e2e8f0;">curl -sf https://agenticcontrolplane.com/install.sh | bash</code></pre>
    <p style="margin:-8px 0 16px;font-size:12.5px;color:var(--color-text-secondary,#6b7280);">Windows &mdash; in PowerShell: <code data-track="Scan: PowerShell Install Copy" style="background:#0f172a;color:#e2e8f0;border-radius:4px;padding:2px 7px;">irm https://agenticcontrolplane.com/install.ps1 | iex</code></p>
    <div style="display:flex;flex-wrap:wrap;gap:10px;">
      <a href="https://cloud.agenticcontrolplane.com/login?from=%2Fonboarding" class="acp-btn acp-btn-primary" style="font-size:14px;">Try ACP free</a>
      <a href="/for-coding-agents" class="acp-btn" style="font-size:14px;">ACP for coding agents &rarr;</a>
      <a href="/blog/mcp-security-checklist-for-enterprise/" class="acp-btn" style="font-size:14px;">Read the security checklist</a>
    </div>
  </div>

</div>

<style>
  #example-cards {
    display: grid;
    grid-template-columns: repeat(3, 1fr);
    gap: 16px;
  }
  .scan-example-btn:hover {
    box-shadow: 0 0 0 2px var(--color-accent) !important;
  }
  @media (max-width: 640px) {
    #example-cards { grid-template-columns: 1fr !important; }
    .scan-vuln-grid { grid-template-columns: 1fr !important; }
  }
</style>
<script src="/assets/js/scanner.js"></script>

<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "WebApplication",
  "name": "MCP Tool Schema Scanner",
  "description": "Browser-side scanner for MCP (Model Context Protocol) tool schemas. Paste a tools/list response and it annotates the lines that allow path traversal, SSRF, injection, and destructive operations.",
  "url": "https://agenticcontrolplane.com/scan/",
  "applicationCategory": "SecurityApplication",
  "operatingSystem": "Any",
  "offers": { "@type": "Offer", "price": "0", "priceCurrency": "USD" }
}
</script>
