Ferrok is an API-first security scanner for Model Context Protocol. One API call finds tool poisoning, excessive permissions, and supply chain risks before your AI agents go live.
Catches hidden prompt injection, stealth instructions, data exfiltration, and zero-width character attacks in tool descriptions.
Flags code execution, filesystem access, database queries, network calls, and credential exposure. Enforces least-privilege.
Identifies missing schemas, unconstrained inputs, weak type definitions, and description-schema mismatches.
Detects insecure HTTP, hardcoded secrets, npx supply chain risks, deprecated transports, and shell injection.
Returns a clear PASS or FAIL with every scan. Drop into GitHub Actions or any pipeline to block unsafe deploys.
Every finding maps to the official framework. Credible, auditable reports your security team will trust.
POST your MCP server JSON to the /v1/scan endpoint.
Four scanners analyze tools, permissions, schemas, transport, and env vars.
Receive structured JSON with a score, grade, pass/fail verdict, and findings.
Get a free API key instantly. 100 scans/month, no credit card.