Features How It Works Pricing Docs Blog Dashboard
v1.0 Live — Full OWASP MCP Top 10 Coverage

Stop shipping vulnerable MCP servers to production.

Ferrok is an API-first security scanner for Model Context Protocol. One API call finds tool poisoning, excessive permissions, and supply chain risks before your AI agents go live.

terminal
# Scan an MCP server config in one call curl -X POST https://api.ferrok.dev/v1/scan \ -H "Authorization: Bearer YOUR_API_KEY" \ -d '{ "config": { "server_url": "https://my-mcp-server.com", "tools": [{ ... }] } }' # Response { "summary": { "score": 42, "grade": "D-", "pass_fail": "FAIL" } }
100
Free Scans / Month
4
Specialized Scanners
<2s
Average Scan Time
0
Credit Cards Required

Everything you need to ship secure agents.

Four specialized scanners working together, mapped to the OWASP MCP Top 10.

Tool Poisoning Detection

Catches hidden prompt injection, stealth instructions, data exfiltration, and zero-width character attacks in tool descriptions.

🔒

Permission Analysis

Flags code execution, filesystem access, database queries, network calls, and credential exposure. Enforces least-privilege.

📄

Schema Validation

Identifies missing schemas, unconstrained inputs, weak type definitions, and description-schema mismatches.

📡

Transport Security

Detects insecure HTTP, hardcoded secrets, npx supply chain risks, deprecated transports, and shell injection.

CI/CD Gate

Returns a clear PASS or FAIL with every scan. Drop into GitHub Actions or any pipeline to block unsafe deploys.

📈

OWASP Mapping

Every finding maps to the official framework. Credible, auditable reports your security team will trust.

Three steps. Seconds to scan.

No agents to install. No dashboards to configure. Just an API call.
1

Send your config

POST your MCP server JSON to the /v1/scan endpoint.

2

We scan everything

Four scanners analyze tools, permissions, schemas, transport, and env vars.

3

Get your report

Receive structured JSON with a score, grade, pass/fail verdict, and findings.

Start free. Scale when ready.

Generous free tier for evaluation. Usage-based pricing that grows with you.
Free
$0/mo
Evaluation & personal projects
  • 100 scans / month
  • All 4 scanners
  • JSON responses
  • Community support
  • Single API key
Get Started
Starter
$9/mo
Indie devs & small teams
  • 500 scans / month
  • All 4 scanners
  • Up to 3 API keys
  • CI/CD scan reports
  • Email support (48h SLA)
Enterprise
Custom
Organizations needing SLAs
  • 50,000+ scans / month
  • Unlimited API keys
  • Custom scanner rules
  • Webhook notifications
  • SLA guarantee (99.9%)
  • Dedicated support & onboarding
Contact Us

Your MCP servers are exposed. Fix that.

Get a free API key instantly. 100 scans/month, no credit card.