MCPShield Agent
AI Agent Security Scanner - Discovers MCP servers on your system and reports them to MCPShield for security analysis.
Installation
# Install from PyPI
pip install mcpshield-agent
# Or install from source
pip install -e .
Quick Start
# Scan your machine and see a local risk score. No account needed.
pip install mcpshield-agent
mcpshield scan
mcpshield scan discovers your MCP servers and prints a 0-100 risk score for
each, computed locally. Sign up (free) and configure --api-key to add CISA KEV
enrichment, org-wide tracking, history, and alerts:
mcpshield configure --api-key mcp_sk_your_key_here
mcpshield scan # now also reports to the dashboard
mcpshield status
Embed the scorer
The risk scorer is a pure function you can drop into any runtime to score an MCP server config in three lines:
from mcpshield_agent import score_config, risk_level
result = score_config({
"server_type": "@modelcontextprotocol/server-filesystem",
"command": "npx -y @modelcontextprotocol/server-filesystem /",
"scope": "/",
"env_vars": ["AWS_SECRET_ACCESS_KEY"],
})
# {"score": 100.0, "level": "critical", "factors": [...], "details": {...}}
It is the same weighted model as the hosted engine (minus CISA KEV enrichment, which stays server-side) and has no network dependency.
Risk-oracle MCP server
Expose the same scorer as an MCP server, so any MCP-capable agent (a SOC agent, Claude Desktop, Cursor) can consult MCPShield as a risk authority before it trusts or invokes an MCP server:
pip install 'mcpshield-agent[mcp]' # needs Python 3.10+
mcpshield-mcp # runs as a stdio MCP server
Register it with any MCP client, e.g. an mcp_servers.json entry:
{ "name": "mcpshield", "command": "mcpshield-mcp" }
Tools it exposes:
| Tool | Purpose |
|---|---|
score_mcp_server |
Score one server from its launch spec (command, args, env) — the risk-authority call |
scan_mcp_config |
Score every server in a config file's contents (standard / Zed / Continue.dev shapes) |
scan_local_machine |
Discover and score every MCP server configured on this host |
Each returns a 0-100 risk_score, a risk_level, and the risk_factors behind
it. Scoring is local and deterministic, and credential values are never
returned — only the credential type appears in the factors, and an inline
credential in a URL-style scope is masked.
Commands
| Command | Description |
|---|---|
mcpshield configure --api-key KEY |
Configure agent with API key |
mcpshield scan |
Scan and score locally; also report if configured |
mcpshield scan --deep |
Also connect to active servers and scan tool descriptions |
mcpshield scan --dry-run |
Scan and score locally, never report |
mcpshield daemon |
Run continuous scheduled scanning |
mcpshield status |
Show agent status |
mcpshield list |
List found servers (no report) |
mcpshield --version |
Show version |
What It Scans
The agent looks for MCP server configurations in:
Windows:
%APPDATA%\Claude\claude_desktop_config.json%APPDATA%\Cursor\User\globalStorage\saoudrizwan.claude-dev\settings\cline_mcp_settings.json%APPDATA%\Windsurf\mcp_settings.json%APPDATA%\Zed\settings.json
macOS:
~/Library/Application Support/Claude/claude_desktop_config.json~/.cursor/mcp.json~/.config/zed/settings.json~/.continue/config.json
Linux:
~/.config/Claude/claude_desktop_config.json~/.config/cursor/mcp.json~/.config/zed/settings.json~/.continue/config.json
Zed servers are read from context_servers; Continue.dev from
experimental.modelContextProtocolServers.
What It Reports
For each discovered MCP server:
- Server name - e.g., "filesystem", "postgres"
- Server type - e.g., "@modelcontextprotocol/server-filesystem"
- Command - Full command string
- Scope - Access scope (file paths, URLs)
- Environment variables - Names only, NOT values
- Status - Active or dormant
Configuration
Config is stored in:
- Windows:
%LOCALAPPDATA%\MCPShield\config.json - macOS:
~/Library/Application Support/MCPShield/config.json - Linux:
~/.config/mcpshield/config.json
{
"api_url": "https://api.mcpshield.app",
"api_key": "mcp_sk_..."
}
Daemon Mode (Continuous Scanning)
Run the agent in daemon mode for automatic scheduled scanning:
# Default: scan every hour (3600 seconds)
mcpshield daemon
# Custom interval: scan every 5 minutes
mcpshield daemon --interval 300
The daemon will:
- Scan for MCP servers at the configured interval
- Report discovered servers to the backend
- Send heartbeat updates
- Log each scan cycle
- Shut down gracefully on Ctrl+C
Security
- Never sends credential values - Only environment variable names
- Local config is secure - API key stored locally
- HTTPS by default - All API communication encrypted
Development
# Install in development mode
pip install -e .
# Run tests
pytest
# Run locally against dev API
mcpshield configure --api-key YOUR_KEY --api-url http://localhost:8000
License
MIT License - see LICENSE file.
Metadata
Release files for mcpshield-agent 0.6.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mcpshield_agent-0.6.0.tar.gz | 28.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mcpshield_agent-0.6.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 52.6 kB
Release files / mcpshield_agent-0.6.0.tar.gz
| Download URL | mcpshield_agent-0.6.0.tar.gz |
|---|---|
| Size | 28.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a56a2a2554c3938282fd927e7eadbdeb1a2c77281b390c81d318de03a977d5e5
|
|
BLAKE2b-256 checksum How to use checksums |
a27eb1f86dced90e0e884a4e3f9bd9fe09368fbc82603c409337c90291c912aa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Release files / mcpshield_agent-0.6.0-py3-none-any.whl
| Download URL | mcpshield_agent-0.6.0-py3-none-any.whl |
|---|---|
| Size | 24.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
61fae5af7bee7fcb2db5efa0053822fc61fc93225a71a3e37c59efadb59e375b
|
|
BLAKE2b-256 checksum How to use checksums |
e53bbbe3ca4b032a775cf8afb15b3d62050165ee3b59e3883ac973237596405d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|