Learn MCP security
The eight checks Hecate runs, where it runs, and plain-language guides to the ways MCP tools turn on the agents that trust them.
turn on your agent.
Deterministic rules, mapped to the OWASP MCP Top 10.
- MCP001
Tool poisoning
Hidden instructions anywhere in a tool’s definition, parameter descriptions included: overrides, secrecy, exfiltration, hidden text.
- MCP002
Rug pulls
Tool definitions that change after you approved them, caught against a lockfile you commit.
- MCP003
Tool shadowing
A tool that tells the model how another server’s tools should behave, such as a silent BCC.
- MCP004
Excessive scope
Tools that run commands, write files steered by untrusted input, or get your whole disk.
- MCP005
Lethal trifecta
Untrusted content, private data and a way out, across every server one agent uses.
- MCP006
Secrets exposure
API keys, tokens and passwords in plain text in client configs and tool definitions.
- MCP007
Known-bad servers
Known-malicious or vulnerable packages, plus the allow and deny lists you set.
- MCP008
Unpinned sources
Packages without a version, images tagged
latest, and remote servers over plain HTTP.
Point it at a client config and add --connect to start each server and list its tools. Results come out as text, JSON, or SARIF for GitHub code scanning.
- Claude Desktop
- Claude Code
- Cursor
- VS Code
- Windsurf
- GitHub code scanning
docs.
Plain-language guides, with real attacks and the commands that catch them.
- Start here
MCP security: a practical guide
How agents get attacked through their tools, and the four habits that stop it.
- Attack
MCP tool poisoning
Instructions hidden in a tool description, and how to find them.
- Attack
MCP rug pulls
Tools that change after you approve them, and how pinning stops it.
- Attack
MCP tool shadowing
When one server's description hijacks another server's tools.
- Attack
The lethal trifecta
Why private data, untrusted content and a way out must never meet.
- Reference
OWASP MCP Top 10
Each risk explained, and what you can check for today.
- Reference
MCP scanners compared
Hecate, Snyk Agent Scan, Cisco MCP Scanner and Proximity, side by side.
- Docs
Detection rules
MCP001 to MCP008: what each finds, its severity, and how to fix it.
- Docs
Quickstart and CI
Scan your configs, pin tool definitions, and run Hecate in GitHub Actions.
What is MCP security?
MCP (Model Context Protocol) security is protecting AI agents from the tools they connect to. An MCP server’s tool names and descriptions are read by the model as trusted text, and its tools can read data and act on the world. MCP security covers the attacks that abuse this: tool poisoning, rug pulls, tool shadowing, prompt injection that steals data (the lethal trifecta), leaked credentials in client configs, and malicious or vulnerable server packages. Start with the practical guide.
What does Hecate check?
Eight rules: tool poisoning (MCP001), rug pulls against a pinned lockfile (MCP002), tool shadowing across servers (MCP003), excessive scope such as command execution (MCP004), the lethal trifecta across all of an agent’s servers (MCP005), plaintext secrets (MCP006), known-malicious or vulnerable packages (MCP007), and unpinned or insecure server sources (MCP008). Each is described in the rule reference.
Does Hecate send my tool definitions or configs anywhere?
No. The scanner runs entirely on your machine with deterministic rules: no LLM calls, no API, no account and no telemetry. Secrets it finds are reported by location and type, never printed. With --connect it starts the servers in your config (running their commands) only because you asked it to.
Is Hecate free and open source?
Yes. The hecate-mcp scanner and the @hecate-mcp/sdk runtime guard are Apache-2.0 licensed and free to use, including in CI. Hecate Cloud, a hosted service for teams, is in early access; join the waitlist to hear when it opens.
How is Hecate different from other MCP scanners?
Hecate is fully local and deterministic, commits a lockfile of approved tool definitions so CI catches rug pulls, analyses risk across every server one agent uses rather than one server at a time, writes SARIF for GitHub code scanning, and has a runtime guard SDK. Scanners that use an LLM or a hosted API can catch rephrased attacks its patterns miss, at the cost of sending your tool definitions to a model or service. See the comparison.
Which MCP clients does Hecate support?
Hecate reads the MCP configs of Claude Desktop, Claude Code (.mcp.json), Cursor, VS Code (.vscode/mcp.json) and Windsurf, as well as raw tools/list JSON. The runtime guard wraps clients built with the official TypeScript MCP SDK, or any MCP transport.