You can't answer that. That's the exposure. MCPShield discovers every unauthorized MCP server across your organization, and what Claude, ChatGPT, and other AI tools can reach, before attackers do.
Instant risk report from your claude_desktop_config.json — no signup, runs entirely in your browser.
MCP servers give AI assistants direct access to databases, file systems, and APIs. Security teams have zero visibility.
Developers configure MCP servers with database credentials, API keys, and file system access. You can't secure what you can't see.
MCP configs often contain plaintext passwords, API tokens, and connection strings. One leaked config = full database access.
AI tools with uncontrolled data access violate SOC 2, HIPAA, GDPR, and the NIST AI RMF. Auditors are starting to ask about AI governance.
This is what a single ungoverned MCP server actually exposes — the chain your security team can't currently see.
MCPShield maps every hop of this chain and risk-scores it before an attacker — or a jailbroken prompt — ever walks it.
MCPShield scans every machine, discovers every MCP server, and assesses every risk—automatically.
Deploy a lightweight agent that scans for MCP configurations across Claude Desktop, Cursor, VS Code, and custom setups. No manual inventory needed.
Our engine analyzes each MCP server's configuration to calculate a risk score from 0-100. Prioritize what matters most.
Run scans whenever you need them. Get a complete inventory of every MCP server on a machine in seconds.
Critical findings are surfaced immediately in your dashboard so your team can act fast on high-risk configurations.
Get your first security insights in under 5 minutes.
Install our lightweight Python agent on endpoints. One pip command, works everywhere.
pip install mcpshield-agent
Configure your agent with an API key, then run a scan to discover MCP configs.
mcpshield configure --api-key YOUR_KEYmcpshield scan
See all servers in your dashboard with risk scores. Take action on high-risk configurations.
mcpshield scan --report
Watch MCPShield discover MCP servers in real-time.
Simulates a scan discovering MCP servers
Give your team instant visibility into MCP server risk. Embed dynamic risk score badges in your internal wikis, READMEs, or Confluence pages. Badges update in real-time as your security posture changes.
Drop MCPShield into your pipeline and every pull request that touches an MCP config gets risk-scored automatically, using the same engine as the dashboard. Free and open source, running in under a minute. No signup, no API key, and nothing leaves the runner.
- uses: RunTimeAdmin/mcpshield-action@v1
with:
fail-on: high
Statically scores committed mcp.json, cline_mcp_settings.json, and claude_desktop_config.json files, then fails the check on risky servers before they ever reach a developer's machine.
Get MCPShield running with a single command. Alerts ship today to Slack and any webhook; more package managers and SIEM connectors are on the roadmap.
pip install mcpshield-agent
Available now on PyPI. Works on Windows, macOS, and Linux.
Risk alerts ship today to Slack and any generic webhook, so you can wire MCPShield into PagerDuty, OpsGenie, Teams, or your own automation.
On the roadmap: Homebrew, APT & RPM packages · Splunk (HEC) · Elastic / ELK · Microsoft Sentinel.
Start free. Upgrade when your team grows.
Free
Up to 3 agents and 50 MCP servers. No credit card needed.
Enterprise
For teams with advanced security and compliance needs. Contact us to discuss requirements.
Agent is MIT licensed and open source. Self-host the full platform free from source.
Start discovering shadow AI agents in your infrastructure today. Free tier included — no credit card required.