Your MCP server has vulnerabilities.
Find them in 2 minutes.

Multi-layer security scans for AI-generated code and MCP servers. Detects leaked API keys, PII, prompt injection, and insecure configs.

Pro doesn't sell scans — it sells client-ready proof. PDF reports, Evidence Packs, verified badges.

View on GitHub
terminal
$ npx project-shield scan ./my-mcp-server 🔍 Scanning 47 files... ✗ CRITICAL F001 API Key Exposed src/config.ts:12 AKIA5EXAMPLE... Detection: regex + entropy(4.8) + context("aws_key") ✗ CRITICAL F003 Prompt Injection tools/search.ts:45 "ignore previous instructions..." Detection: keyword + structure ⚠ WARNING F002 MCP No Auth mcp.json:1 No authentication configured ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Score: 12/100 (F) | Status: 🔒 LOCKED 2 Critical · 1 Warning · 0 Info Fix-it guide: 3 actionable fixes available Badge: Locked — resolve critical issues first

MCP is the new attack surface

AI-generated code ships fast — but security doesn't keep up. MCP servers introduce an entirely new class of vulnerabilities.

7.2%
of MCP servers have exploitable vulnerabilities
arXiv:2506.13538 — 1,899 servers analyzed
5.5%
~45%
of AI-generated code has security flaws
Veracode 2025 State of Software Security

Multi-Layer Detection

One layer misses. The next catches. Each vulnerability goes through 2–3 independent detection methods.

1

Pattern Matching

Known vulnerability signatures — regex patterns for API keys (AWS, Stripe, OpenAI…), PII formats, injection keywords, and MCP misconfigurations.

2

Entropy & Checksum

Mathematical verification — Shannon entropy analysis catches unknown key formats. Luhn algorithm validates card numbers. Checksum verifies national IDs.

3

Context Analysis

Smart filtering — variable names, file paths, and surrounding code determine if a match is a real threat or a false positive (test data, examples, comments).

3 layers for secrets · 2 layers for PII · 2 layers for injection · 5 checks for MCP

Scan the code. Audit the agent.

Both run from your terminal. No signup, and neither command uploads the files it inspects.

🔍

npx project-shield scan .

Reads the eligible files under the path you give it, on your machine, and reports what it finds. It does not rewrite the files it scans — --fix prints remediation guidance instead of patching code.

A successful scan increments a monthly usage count in ~/.project-shield/. A badge or Evidence Pack file is written only when you pass --badge or --evidence. With no license key on the machine the scan makes no network call; if an already-stored Pro license cache has expired, the CLI contacts Polar to re-validate it.

⚙️

npx project-shield audit

A separate check for the AI-agent environment itself: 9 environment checks and 7 hook checks over your Claude Code settings files, CLAUDE.md, .env, and hook definitions.

Hook commands and configuration are read and pattern-matched — never executed. Free runs 3 audits a month and shows the full score with the free-tier environment findings; Pro runs 20 and adds the remaining environment findings, the hook findings, JSON output, and the audit Evidence Pack. The result is recorded in .claude/.shield/audit-state.json so a later run can flag configuration changes.

Critical vulnerability? Badge locked.

No false sense of security. If critical issues exist, your Scan Badge won't be issued until they're fixed. Fix-it guide included.

A
Excellent ✅
All checks passed
B–C
Pass ✅
Clean Scan Badge
D–E
Warning ⚠️
Badge with warning tag
F
Locked 🔒
Fix required to unlock

Not just a scan. A verifiable proof.

Every scan produces tamper-proof evidence. Clients can independently verify your security posture.

🔐

Unique Badge ID

A Pro scan seals a badge UUID and a verify-URL field into the Evidence Pack. That UUID and the SHA-256 result hash are what you hand a client — this site does not host a badge lookup page today.

🔏

Hash-Sealed Results

Scan results are sealed with SHA-256 hash. Any modification is instantly detectable.

📋

Evidence Pack

Full scan metadata — timestamp, ruleset version, file count, findings summary — bundled in a verifiable package.

🛡️

Ruleset Integrity

Expert-curated rules with SHA-256 verification. Tampered rulesets are rejected before scanning begins.

Scan → Evidence → Trust

Open the sample JSON

Synthetic example. It was produced by the v2.0.0 Evidence Pack code with made-up findings — it is not a customer report, not a certification, and not a live verification. Every file path, finding, and identifier in it is invented.
File SHA-256: a0e6db41b86cc13d08a35906c8ecf4c5e74c570ddb5db93bed6af1316d80353b

Why not just ask AI to check your security?

AI (ChatGPT / Claude) Project Shield
MCP-specific rules Generic advice Research-based rules
Detection layers Single pass Multi-layer (2–3×)
Verifiable output Chat response Sealed Evidence Pack
False positive mgmt None shield-ignore + tuned thresholds
Client proof Screenshot? Verified Scan Badge + URL

Block vulnerabilities before they ship.

Add one step to your GitHub Actions. Shield fails the build if critical issues are found.

.github/workflows/shield.yml
name: Security Scan on: [push, pull_request] jobs: shield: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Run Shield run: npx project-shield scan . --ci

Shield exits with code 1 on critical findings — your CI pipeline stops automatically.

Start free. Upgrade when you need proof.

Two offers are live today: Free and Pro. No credit card required to scan.

Free
$0
For individual developers
  • 5 scans / month
  • 3 environment audits / month
  • Terminal report
  • Watermarked Scan Badge
  • Lock system applied
  • Fix-it guide (summary)

Free to scan. Locked until safe.
Verified when ready.

Run your first scan in under a minute. No signup required.

npx project-shield scan .

Click to copy