ToolTrust Scanner is a Model Context Protocol (MCP) server: Scans MCP servers for prompt injection, data exfiltration, and privilege escalation. Because it speaks the Model Context Protocol, AI assistants can use ToolTrust Scanner as a set of callable tools instead of you copy-pasting between apps.
It runs locally: the npm package tooltrust-mcp speaks MCP over stdio on your machine. No credentials are required — it works out of the box. The current release is v1.0.9, published under the MIT license, with source at AgentSafe-AI/tooltrust-scanner on GitHub, where it has earned 19 stars.
On mcp.site, ToolTrust Scanner sits in the Security category. Any MCP client can use it — Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Zed among them — via the install snippets below. If you maintain ToolTrust Scanner for AgentSafe-AI, claim this listing to verify ownership, earn the Verified badge, and keep the details current.
▸npm package — tooltrust-mcp · MCP over stdio
▸Open source — MIT license · AgentSafe-AI/tooltrust-scanner