Skip to main content

MCPShield Agent

AI Agent Security Scanner - Discovers MCP servers on your system and reports them to MCPShield for security analysis.

Installation

# Install from PyPI
pip install mcpshield-agent

# Or install from source
pip install -e .

Quick Start

# Scan your machine and see a local risk score. No account needed.
pip install mcpshield-agent
mcpshield scan

mcpshield scan discovers your MCP servers and prints a 0-100 risk score for each, computed locally. Sign up (free) and configure --api-key to add CISA KEV enrichment, org-wide tracking, history, and alerts:

mcpshield configure --api-key mcp_sk_your_key_here
mcpshield scan     # now also reports to the dashboard
mcpshield status

Embed the scorer

The risk scorer is a pure function you can drop into any runtime to score an MCP server config in three lines:

from mcpshield_agent import score_config, risk_level

result = score_config({
    "server_type": "@modelcontextprotocol/server-filesystem",
    "command": "npx -y @modelcontextprotocol/server-filesystem /",
    "scope": "/",
    "env_vars": ["AWS_SECRET_ACCESS_KEY"],
})
# {"score": 100.0, "level": "critical", "factors": [...], "details": {...}}

It is the same weighted model as the hosted engine (minus CISA KEV enrichment, which stays server-side) and has no network dependency.

Commands

Command Description
mcpshield configure --api-key KEY Configure agent with API key
mcpshield scan Scan and score locally; also report if configured
mcpshield scan --deep Also connect to active servers and scan tool descriptions
mcpshield scan --dry-run Scan and score locally, never report
mcpshield daemon Run continuous scheduled scanning
mcpshield status Show agent status
mcpshield list List found servers (no report)
mcpshield --version Show version

What It Scans

The agent looks for MCP server configurations in:

Windows:

  • %APPDATA%\Claude\claude_desktop_config.json
  • %APPDATA%\Cursor\User\globalStorage\saoudrizwan.claude-dev\settings\cline_mcp_settings.json

macOS:

  • ~/Library/Application Support/Claude/claude_desktop_config.json

Linux:

  • ~/.config/Claude/claude_desktop_config.json
  • ~/.config/cursor/mcp.json

What It Reports

For each discovered MCP server:

  • Server name - e.g., "filesystem", "postgres"
  • Server type - e.g., "@modelcontextprotocol/server-filesystem"
  • Command - Full command string
  • Scope - Access scope (file paths, URLs)
  • Environment variables - Names only, NOT values
  • Status - Active or dormant

Configuration

Config is stored in:

  • Windows: %LOCALAPPDATA%\MCPShield\config.json
  • macOS: ~/Library/Application Support/MCPShield/config.json
  • Linux: ~/.config/mcpshield/config.json
{
  "api_url": "https://api.mcpshield.app",
  "api_key": "mcp_sk_..."
}

Daemon Mode (Continuous Scanning)

Run the agent in daemon mode for automatic scheduled scanning:

# Default: scan every hour (3600 seconds)
mcpshield daemon

# Custom interval: scan every 5 minutes
mcpshield daemon --interval 300

The daemon will:

  • Scan for MCP servers at the configured interval
  • Report discovered servers to the backend
  • Send heartbeat updates
  • Log each scan cycle
  • Shut down gracefully on Ctrl+C

Security

  • Never sends credential values - Only environment variable names
  • Local config is secure - API key stored locally
  • HTTPS by default - All API communication encrypted

Development

# Install in development mode
pip install -e .

# Run tests
pytest

# Run locally against dev API
mcpshield configure --api-key YOUR_KEY --api-url http://localhost:8000

License

MIT License - see LICENSE file.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mcpshield_agent-0.3.0.tar.gz (22.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mcpshield_agent-0.3.0-py3-none-any.whl (19.7 kB view details)

Uploaded Python 3

File details

Details for the file mcpshield_agent-0.3.0.tar.gz.

File metadata

  • Download URL: mcpshield_agent-0.3.0.tar.gz
  • Upload date:
  • Size: 22.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for mcpshield_agent-0.3.0.tar.gz
Algorithm Hash digest
SHA256 dfb4b56861bd0ecb6f368bd852114b89961908af9b364145006b2dc7a2ec2574
MD5 5ff0c5afdc8e864bc492785a32618fe4
BLAKE2b-256 11fbfba1f9df921cd6de7704f81152db563195c1c33958e4183966a33255bfb1

See more details on using hashes here.

File details

Details for the file mcpshield_agent-0.3.0-py3-none-any.whl.

File metadata

File hashes

Hashes for mcpshield_agent-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 bdee385b3c1d2906f0e46546c76bd6354fe24e93d00ec531cce138f4a2a6d67a
MD5 1a37dc9d37393466bfefadfe32c11f61
BLAKE2b-256 e2c00a045f9fce7dfbb0309a2ab1d273cd731df12d92ab22db46204c50a5f62a

See more details on using hashes here.

Release history Release notifications | RSS feed

0.6.0

2 files

0.5.0

2 files

0.4.0

2 files

This release

0.3.0 This release

2 files

0.2.1

2 files

0.2.0

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page