Skip to main content

HEXIS MCP GUARD

Security scanner for MCP (Model Context Protocol) servers.

Install

pip install git+https://github.com/Noumenon-ai/hexis-mcp-guard.git

Or from source:

git clone https://github.com/Noumenon-ai/hexis-mcp-guard.git
cd hexis-mcp-guard
pip install -e ".[dev]"

Usage

hexis scan ./my-server/
hexis scan --format sarif -o results.sarif ./server/
hexis scan --format json ./server/
hexis scan --url http://localhost:8080 --dynamic
hexis scan ./server/ --ai
hexis scan ./server/ --ci --fail-on high
hexis scan ./server/ --baseline .hexis-baseline.json
hexis rules

Features

  • 14 security rules (SSRF, shell injection, auth, prompt injection, resource exposure, transport)
  • Static analysis + dynamic probing
  • SARIF 2.1.0 output for GitHub Security tab
  • JSON + rich terminal output
  • CI/CD ready (exit codes)
  • Optional AI reasoning (Claude)

Rules

Rule Severity Category Description
HEXIS-AUTH-001 HIGH auth No authentication on transport
HEXIS-AUTH-002 HIGH auth Missing authorization checks on sensitive tools
HEXIS-CMD-001 CRITICAL shell_injection subprocess/exec with user input
HEXIS-CMD-002 CRITICAL shell_injection shell=True with string interpolation
HEXIS-CMD-003 CRITICAL shell_injection eval/exec on tool arguments
HEXIS-PI-001 HIGH prompt_injection Tool description contains injection patterns
HEXIS-PI-002 MEDIUM prompt_injection Return values flow unsanitized to LLM context
HEXIS-PI-003 HIGH prompt_injection Tool poisoning via hidden instructions in descriptions
HEXIS-RES-001 HIGH resource_exposure Unrestricted file system access
HEXIS-RES-002 HIGH resource_exposure SQL query tool without parameterization
HEXIS-SSRF-001 HIGH ssrf URL parameter in tool inputSchema without validation
HEXIS-SSRF-002 CRITICAL ssrf Server-side fetch with user-controlled URL
HEXIS-SSRF-003 CRITICAL ssrf Internal IP/metadata endpoint accessible
HEXIS-TLS-001 MEDIUM transport Plaintext HTTP transport in production

CI/CD Integration

GitHub Actions

- name: MCP Security Scan
  run: |
    pip install git+https://github.com/Noumenon-ai/hexis-mcp-guard.git
    hexis scan ./src --format sarif --output results.sarif --ci --fail-on high

- name: Upload SARIF
  uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: results.sarif

Exit Codes

Code Meaning
0 No HIGH/CRITICAL findings
1 HIGH findings detected
2 CRITICAL findings detected

License

MIT

Built by Noumenon

Metadata

Release files for hexis-mcp-guard 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hexis-mcp-guard 0.1.0
File Size Uploaded
hexis_mcp_guard-0.1.0.tar.gz 30.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hexis-mcp-guard 0.1.0
File Interpreter ABI Platform
hexis_mcp_guard-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 63.3 kB

Release files / hexis_mcp_guard-0.1.0.tar.gz

Download URL hexis_mcp_guard-0.1.0.tar.gz
Size 30.8 kB
Tags Source
SHA-256 checksum
How to use checksums
5be2d2bdb0bd447b09c46e9ee8d2a01d475703994145e714830844281fc938a7
BLAKE2b-256 checksum
How to use checksums
994a244edcab45f842e950387e74c8317fdbc8a227b19b2558fe3bb55719a2b4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 12, 2026.

Transparency log

Release files / hexis_mcp_guard-0.1.0-py3-none-any.whl

Download URL hexis_mcp_guard-0.1.0-py3-none-any.whl
Size 32.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a1da56cd909fed0bf95154f9e643a827f48026489af1b9d25b5f7814a3990eaf
BLAKE2b-256 checksum
How to use checksums
4569ac7bddb8608832904149a827a95481b62197e0814543ad235154134b9646
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 12, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page