Skip to main content

MCPShield Agent

AI Agent Security Scanner - Discovers MCP servers on your system and reports them to MCPShield for security analysis.

Installation

# Install from PyPI
pip install mcpshield-agent

# Or install from source
pip install -e .

Quick Start

# Scan your machine and see a local risk score. No account needed.
pip install mcpshield-agent
mcpshield scan

mcpshield scan discovers your MCP servers and prints a 0-100 risk score for each, computed locally. Sign up (free) and configure --api-key to add CISA KEV enrichment, org-wide tracking, history, and alerts:

mcpshield configure --api-key mcp_sk_your_key_here
mcpshield scan     # now also reports to the dashboard
mcpshield status

Embed the scorer

The risk scorer is a pure function you can drop into any runtime to score an MCP server config in three lines:

from mcpshield_agent import score_config, risk_level

result = score_config({
    "server_type": "@modelcontextprotocol/server-filesystem",
    "command": "npx -y @modelcontextprotocol/server-filesystem /",
    "scope": "/",
    "env_vars": ["AWS_SECRET_ACCESS_KEY"],
})
# {"score": 100.0, "level": "critical", "factors": [...], "details": {...}}

It is the same weighted model as the hosted engine (minus CISA KEV enrichment, which stays server-side) and has no network dependency.

Risk-oracle MCP server

Expose the same scorer as an MCP server, so any MCP-capable agent (a SOC agent, Claude Desktop, Cursor) can consult MCPShield as a risk authority before it trusts or invokes an MCP server:

pip install 'mcpshield-agent[mcp]'   # needs Python 3.10+
mcpshield-mcp                         # runs as a stdio MCP server

Register it with any MCP client, e.g. an mcp_servers.json entry:

{ "name": "mcpshield", "command": "mcpshield-mcp" }

Tools it exposes:

Tool Purpose
score_mcp_server Score one server from its launch spec (command, args, env) — the risk-authority call
scan_mcp_config Score every server in a config file's contents (standard / Zed / Continue.dev shapes)
scan_local_machine Discover and score every MCP server configured on this host

Each returns a 0-100 risk_score, a risk_level, and the risk_factors behind it. Scoring is local and deterministic, and credential values are never returned — only the credential type appears in the factors, and an inline credential in a URL-style scope is masked.

Commands

Command Description
mcpshield configure --api-key KEY Configure agent with API key
mcpshield scan Scan and score locally; also report if configured
mcpshield scan --deep Also connect to active servers and scan tool descriptions
mcpshield scan --dry-run Scan and score locally, never report
mcpshield daemon Run continuous scheduled scanning
mcpshield status Show agent status
mcpshield list List found servers (no report)
mcpshield --version Show version

What It Scans

The agent looks for MCP server configurations in:

Windows:

  • %APPDATA%\Claude\claude_desktop_config.json
  • %APPDATA%\Cursor\User\globalStorage\saoudrizwan.claude-dev\settings\cline_mcp_settings.json
  • %APPDATA%\Windsurf\mcp_settings.json
  • %APPDATA%\Zed\settings.json

macOS:

  • ~/Library/Application Support/Claude/claude_desktop_config.json
  • ~/.cursor/mcp.json
  • ~/.config/zed/settings.json
  • ~/.continue/config.json

Linux:

  • ~/.config/Claude/claude_desktop_config.json
  • ~/.config/cursor/mcp.json
  • ~/.config/zed/settings.json
  • ~/.continue/config.json

Zed servers are read from context_servers; Continue.dev from experimental.modelContextProtocolServers.

What It Reports

For each discovered MCP server:

  • Server name - e.g., "filesystem", "postgres"
  • Server type - e.g., "@modelcontextprotocol/server-filesystem"
  • Command - Full command string
  • Scope - Access scope (file paths, URLs)
  • Environment variables - Names only, NOT values
  • Status - Active or dormant

Configuration

Config is stored in:

  • Windows: %LOCALAPPDATA%\MCPShield\config.json
  • macOS: ~/Library/Application Support/MCPShield/config.json
  • Linux: ~/.config/mcpshield/config.json
{
  "api_url": "https://api.mcpshield.app",
  "api_key": "mcp_sk_..."
}

Daemon Mode (Continuous Scanning)

Run the agent in daemon mode for automatic scheduled scanning:

# Default: scan every hour (3600 seconds)
mcpshield daemon

# Custom interval: scan every 5 minutes
mcpshield daemon --interval 300

The daemon will:

  • Scan for MCP servers at the configured interval
  • Report discovered servers to the backend
  • Send heartbeat updates
  • Log each scan cycle
  • Shut down gracefully on Ctrl+C

Security

  • Never sends credential values - Only environment variable names
  • Local config is secure - API key stored locally
  • HTTPS by default - All API communication encrypted

Development

# Install in development mode
pip install -e .

# Run tests
pytest

# Run locally against dev API
mcpshield configure --api-key YOUR_KEY --api-url http://localhost:8000

License

MIT License - see LICENSE file.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mcpshield_agent-0.6.0.tar.gz (28.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mcpshield_agent-0.6.0-py3-none-any.whl (24.3 kB view details)

Uploaded Python 3

File details

Details for the file mcpshield_agent-0.6.0.tar.gz.

File metadata

  • Download URL: mcpshield_agent-0.6.0.tar.gz
  • Upload date:
  • Size: 28.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for mcpshield_agent-0.6.0.tar.gz
Algorithm Hash digest
SHA256 a56a2a2554c3938282fd927e7eadbdeb1a2c77281b390c81d318de03a977d5e5
MD5 251f2e2617798b174d211a649f10b682
BLAKE2b-256 a27eb1f86dced90e0e884a4e3f9bd9fe09368fbc82603c409337c90291c912aa

See more details on using hashes here.

File details

Details for the file mcpshield_agent-0.6.0-py3-none-any.whl.

File metadata

File hashes

Hashes for mcpshield_agent-0.6.0-py3-none-any.whl
Algorithm Hash digest
SHA256 61fae5af7bee7fcb2db5efa0053822fc61fc93225a71a3e37c59efadb59e375b
MD5 00678590e1f021f6cfc299d7d61e012d
BLAKE2b-256 e53bbbe3ca4b032a775cf8afb15b3d62050165ee3b59e3883ac973237596405d

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.6.0 This release

2 files

0.5.0

2 files

0.4.0

2 files

0.3.0

2 files

0.2.1

2 files

0.2.0

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page