Skip to main content

Zirah

Find tool poisoning, prompt injection, tool shadowing and leaked secrets in MCP servers before your agent trusts them. Offline, no account, every finding explained.

Zirah reads an MCP server's manifest (its tools, prompts, resources and instructions), runs detection rules over every string the model will see, and gives the server an explainable trust score from 0 to 100. Each finding carries the exact location (a JSON pointer), the evidence, an OWASP MCP Top 10 mapping and a fix. It works fully offline; an LLM judge is optional.

Zirah scanning a benign and a malicious demo MCP server

Install

pipx install zirah-mcp

The package is zirah-mcp; the command it installs is zirah. Zirah needs Python 3.12 or newer. uv tool install zirah-mcp and pip install zirah-mcp work too. On Windows, if Application Control blocks the zirah launcher, run python -m zirah.

Quickstart

zirah scan server.json                          # a manifest: tools/list, prompts/list, resources/list
zirah scan https://mcp.example.com/mcp          # a remote server (Streamable HTTP or SSE)
zirah discover                                  # MCP servers configured on this machine (offline)
zirah scan --all                                # every configured server, one session
zirah scan server.json --format sarif -o zirah.sarif   # GitHub code scanning

Exit code 1 means a finding at or above --fail-on (default high), so Zirah drops into CI as is. Reports come as terminal output, JSON, SARIF 2.1.0 or markdown.

Try it on the harmless demo servers: the malicious one gets grade F with 12 findings, the benign one 100/100.

What it detects

Module Finds OWASP MCP Top 10
D1 Tool poisoning Invisible Unicode, ANSI escapes, homoglyphs, hidden instructions, credential-file requests, covert forwarding, HTML/markdown smuggling, text aimed at the scanner MCP03
D2 Prompt injection Instruction overrides, forged delimiters, jailbreaks, system-prompt extraction, exfiltration, markdown image beacons, scanner evasion in prompts, resources and instructions MCP06
D3 Tool shadowing Tools claiming priority over, overriding or ordering around other tools MCP03
D4 Secrets API keys, tokens, private keys, JWTs, credentials in URLs (always redacted) MCP01
D14 Shadow MCP Configured servers in Claude Desktop, Claude Code, Cursor, VS Code and Windsurf, checked against an approved list MCP09

Rules are YAML, so they can be read, reviewed and extended. The optional LLM judge (--llm ollama|openai|anthropic) adds semantic checks and never removes a static finding.

Running stdio servers

zirah scan --allow-exec <command> starts a local server to read its manifest. This runs the server's code on your machine with your user permissions, with no isolation. Zirah prints a warning, never calls a tool, applies time and size limits and kills the whole process tree afterwards. Prefer a static manifest when you can.

Written and maintained by Muhammad Mohsin Ibrahim. Licensed under Apache-2.0.

Metadata

Release files for zirah-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for zirah-mcp 0.1.0
File Size Uploaded
zirah_mcp-0.1.0.tar.gz 176.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for zirah-mcp 0.1.0
File Interpreter ABI Platform
zirah_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 276.5 kB

Release files / zirah_mcp-0.1.0.tar.gz

Download URL zirah_mcp-0.1.0.tar.gz
Size 176.5 kB
Tags Source
SHA-256 checksum
How to use checksums
5f1c0d58bcf44dfff55626fbf337261234349d0a4cfb9796894260af3109961c
BLAKE2b-256 checksum
How to use checksums
53b30ad7b943f20d8054a72ccd663f10d60e9ad50f0b7753e4962ebbb526c19d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / zirah_mcp-0.1.0-py3-none-any.whl

Download URL zirah_mcp-0.1.0-py3-none-any.whl
Size 99.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6466ec72002dd25bb574643cc4c0fdafd8e286e1cdbb90fb51afc5de5da0affc
BLAKE2b-256 checksum
How to use checksums
72e02f010e2a693bc1fdd72c56c0dea152771040f77e3a4ddb10c80862affe2b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page