Zirah
Find tool poisoning, prompt injection, tool shadowing and leaked secrets in MCP servers before your agent trusts them. Offline, no account, every finding explained.
Zirah reads an MCP server's manifest (its tools, prompts, resources and instructions), runs detection rules over every string the model will see, and gives the server an explainable trust score from 0 to 100. Each finding carries the exact location (a JSON pointer), the evidence, an OWASP MCP Top 10 mapping and a fix. It works fully offline; an LLM judge is optional.
Install
pipx install zirah-mcp
The package is zirah-mcp; the command it installs is zirah. Zirah needs Python 3.12 or
newer. uv tool install zirah-mcp and pip install zirah-mcp work too.
On Windows, if Application Control blocks the zirah launcher, run python -m zirah.
Quickstart
zirah scan server.json # a manifest: tools/list, prompts/list, resources/list
zirah scan https://mcp.example.com/mcp # a remote server (Streamable HTTP or SSE)
zirah discover # MCP servers configured on this machine (offline)
zirah scan --all # every configured server, one session
zirah scan server.json --format sarif -o zirah.sarif # GitHub code scanning
Exit code 1 means a finding at or above --fail-on (default high), so Zirah drops into CI
as is. Reports come as terminal output, JSON, SARIF 2.1.0 or markdown.
Try it on the harmless demo servers: the malicious one gets grade F with 12 findings, the benign one 100/100.
What it detects
| Module | Finds | OWASP MCP Top 10 |
|---|---|---|
| D1 Tool poisoning | Invisible Unicode, ANSI escapes, homoglyphs, hidden instructions, credential-file requests, covert forwarding, HTML/markdown smuggling, text aimed at the scanner | MCP03 |
| D2 Prompt injection | Instruction overrides, forged delimiters, jailbreaks, system-prompt extraction, exfiltration, markdown image beacons, scanner evasion in prompts, resources and instructions | MCP06 |
| D3 Tool shadowing | Tools claiming priority over, overriding or ordering around other tools | MCP03 |
| D4 Secrets | API keys, tokens, private keys, JWTs, credentials in URLs (always redacted) | MCP01 |
| D14 Shadow MCP | Configured servers in Claude Desktop, Claude Code, Cursor, VS Code and Windsurf, checked against an approved list | MCP09 |
Rules are YAML, so they can be read, reviewed and extended. The optional LLM judge
(--llm ollama|openai|anthropic) adds semantic checks and never removes a static finding.
Running stdio servers
zirah scan --allow-exec <command> starts a local server to read its manifest. This runs
the server's code on your machine with your user permissions, with no isolation. Zirah
prints a warning, never calls a tool, applies time and size limits and kills the whole
process tree afterwards. Prefer a static manifest when you can.
Links
Written and maintained by Muhammad Mohsin Ibrahim. Licensed under Apache-2.0.
Metadata
Release files for zirah-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| zirah_mcp-0.1.0.tar.gz | 176.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| zirah_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 276.5 kB
Release files / zirah_mcp-0.1.0.tar.gz
| Download URL | zirah_mcp-0.1.0.tar.gz |
|---|---|
| Size | 176.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5f1c0d58bcf44dfff55626fbf337261234349d0a4cfb9796894260af3109961c
|
|
BLAKE2b-256 checksum How to use checksums |
53b30ad7b943f20d8054a72ccd663f10d60e9ad50f0b7753e4962ebbb526c19d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / zirah_mcp-0.1.0-py3-none-any.whl
| Download URL | zirah_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 99.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6466ec72002dd25bb574643cc4c0fdafd8e286e1cdbb90fb51afc5de5da0affc
|
|
BLAKE2b-256 checksum How to use checksums |
72e02f010e2a693bc1fdd72c56c0dea152771040f77e3a4ddb10c80862affe2b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log