Learn MCP security

The eight checks Hecate runs, where it runs, and plain-language guides to the ways MCP tools turn on the agents that trust them.

Eight checks for the ways MCP tools turn on your agent.

Deterministic rules, mapped to the OWASP MCP Top 10.

Works where your agents live

Reads the MCP configs you already have.

Point it at a client config and add --connect to start each server and list its tools. Results come out as text, JSON, or SARIF for GitHub code scanning.

  • Claude Desktop
  • Claude Code
  • Cursor
  • VS Code
  • Windsurf
  • GitHub code scanning

Guides and docs.

Plain-language guides, with real attacks and the commands that catch them.

Questions

What is MCP security?

MCP (Model Context Protocol) security is protecting AI agents from the tools they connect to. An MCP server’s tool names and descriptions are read by the model as trusted text, and its tools can read data and act on the world. MCP security covers the attacks that abuse this: tool poisoning, rug pulls, tool shadowing, prompt injection that steals data (the lethal trifecta), leaked credentials in client configs, and malicious or vulnerable server packages. Start with the practical guide.

What does Hecate check?

Eight rules: tool poisoning (MCP001), rug pulls against a pinned lockfile (MCP002), tool shadowing across servers (MCP003), excessive scope such as command execution (MCP004), the lethal trifecta across all of an agent’s servers (MCP005), plaintext secrets (MCP006), known-malicious or vulnerable packages (MCP007), and unpinned or insecure server sources (MCP008). Each is described in the rule reference.

Does Hecate send my tool definitions or configs anywhere?

No. The scanner runs entirely on your machine with deterministic rules: no LLM calls, no API, no account and no telemetry. Secrets it finds are reported by location and type, never printed. With --connect it starts the servers in your config (running their commands) only because you asked it to.

Is Hecate free and open source?

Yes. The hecate-mcp scanner and the @hecate-mcp/sdk runtime guard are Apache-2.0 licensed and free to use, including in CI. Hecate Cloud, a hosted service for teams, is in early access; join the waitlist to hear when it opens.

How is Hecate different from other MCP scanners?

Hecate is fully local and deterministic, commits a lockfile of approved tool definitions so CI catches rug pulls, analyses risk across every server one agent uses rather than one server at a time, writes SARIF for GitHub code scanning, and has a runtime guard SDK. Scanners that use an LLM or a hosted API can catch rephrased attacks its patterns miss, at the cost of sending your tool definitions to a model or service. See the comparison.

Which MCP clients does Hecate support?

Hecate reads the MCP configs of Claude Desktop, Claude Code (.mcp.json), Cursor, VS Code (.vscode/mcp.json) and Windsurf, as well as raw tools/list JSON. The runtime guard wraps clients built with the official TypeScript MCP SDK, or any MCP transport.