Your agent connects to tools
nobody has checked.
AI agents now reach MCP servers and APIs that can hide instructions and steal credentials without the agent — or you — noticing. Paste one, and see exactly what it would do.
automate it with the one-line agent rule
TOOLPROOF VERDICT — mcp.context7.com grade: A+ (100/100) · state: verified · kind: mcp Clean scan — no agent-hijack patterns found. + HTTPS enforced + Server instructions captured and reviewed + MCP surface verified — 2 tool(s) inspected review card: toolproof-scan.vercel.app/t?target=…
Any MCP server or API you're about to connect to.
15 checks — hidden instructions, exposed secrets, unsafe defaults, missing auth.
A+ means clean. Anything less shows exactly why, with evidence.
Prefer zero effort? Put one line in your agent's instructions and it checks every tool itself — the agent rule.
Tools can lie to your AI.
When an AI connects to a tool, the tool's description goes straight into the model's context — and the model obeys it. Attackers hide instructions there in invisible characters: you see nothing, the model reads every word. Toggle the views:
Each issue lowers the score: critical −45, high −25, medium −12, low −5. Full methodology in the API docs.
Well-known tools, scanned live as this page loads. Today's scan, not an endorsement.
Every verdict you pull is kept in this browser — your private receipt book.
Know what your agent is about to trust.
How do I check if an MCP server is safe?+
Paste its URL into Toolproof. The scanner returns a letter grade and the evidence behind it, including hidden instructions in tool descriptions, invisible characters, exposed secrets, unsafe defaults and missing authentication signals.
What is an MCP prompt injection attack?+
A malicious tool can put instructions in the text an AI model reads. Those instructions can tell the model to ignore safeguards, expose data or contact another service. Some attacks use invisible Unicode characters, so the text can look harmless to a person.
Can my AI agent check tools automatically?+
Yes. Add the Toolproof rule to the agent's instructions or install the Toolproof MCP server. The agent can verify an unfamiliar MCP server or API before it connects and report the grade to the user.
Are Toolproof verdicts verifiable?+
Every verdict includes an ed25519-signed passport over canonical JSON. You can verify the signature offline with standard cryptography libraries, without trusting Toolproof code at verification time.
Need the technical details? Read the API docs or set up the agent rule.
One rule in your agent's config makes it check unfamiliar tools before connecting.
The safest and most flagged tools, ranked from reproducible scans. Plus your watchlist.
Pin a tool and get flagged when its model-visible text changes. Mint canary credentials to trap leaks.
Keyless API: signed verdicts and full findings, one GET each.