MCP & Claude Code security scanner — threat-models plugins, MCP servers, hooks, skills & connectors with an LLM before you trust them. Catches prompt injection, tool poisoning & credential exfiltratio
Assay is an MCP & Claude Code security scanner. It threat-models plugins, MCP servers, hooks, skills & connectors with an LLM — not regex — to catch prompt injection, credential exfiltration, and MCP tool poisoning before you trust them. Runs on your Claude Code subscription — no separate API key required.
📚 Documentation · Install · Quickstart · How it works · FAQ
▶ Demo — inventory your Claude Code stack, then threat-model and scan an MCP server end to end.
https://github.com/user-attachments/assets/8e6e1c3f-358a-4cf1-a50c-6e15fbf43c75
Before you install a plugin or wire up an MCP server, Assay threat-models what it could do, then reads the code for evidence — every finding backed by a verbatim file:line quote. It's built for MCP security and the wider Claude Code attack surface, where the dangerous behavior is usually legal code with bad intent that SAST and dependency scanners miss.
- Reasons, doesn't pattern-match — an LLM builds a threat model before it reads source, so the review is hypothesis-driven, not regex. - Catches AI-native threats — prompt injection, MCP tool poisoning, credential exfiltration, hook abuse, capability-vs-claim mismatch. - No confabulation — a post-validator re-reads every citation and drops anything the model can't back with real code. - Runs on your subscription — default mode drives Claude Code via claude -p; no separate API key, no rate-limit walls. - One binary, three roles — the CLI, the assay serve web UI, and the assay mcp server Claude Code drives.
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/chawdamrunal--assay.html)
MCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads
KernelLord/pickysteveSkill router and context picker for Claude Code, Cursor, and Aider. Auto-picks the right skill for every prompt, with prompt-injection filtering for MCP.
hung12ct/culiSelf-improving context & memory for Claude Code and OpenAI Codex. One canonical knowledge store injected only when relevant — hooks push budgeted context, an MCP server serves depth on demand, and it
0xwilliamortiz/openclaude-improvedruns anywhere. uses anything
flankerhqd/cyvisguardSecurity control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.
Gowthaman90/mcp-bastionReliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.