Paste a tool description, an .mcp.json, or the server code you found on GitHub.
This checks it for the exact patterns behind real incidents — hidden Unicode, instructions aimed at the agent instead of you, and known-malicious packages — entirely in your browser.
The same three checks that ship in the SecureAI-Scan CLI — reused here so you can run them before you've even cloned anything.
Zero-width, bidirectional, and tag-block characters that hide text from your eyes while a model still reads it.
Instructions aimed at the agent, not you — "ignore previous instructions," concealment from the user, reads of ~/.ssh, exfil to a URL.
Checked against documented incidents — the postmark-mcp backdoor, published CVEs — not guesswork.