# @guardbee/mcp-tool-poisoning-scanner

> MCP server that scans other MCP servers' tool definitions for tool poisoning (hidden instructions embedded in a tool's description, read as trusted context by the calling LLM) and confused-deputy mismatches (a tool's name/description promises read-only be

Latest version **0.1.0** (published 2026-09-24) · MIT license · 0 weekly downloads

_The full health report (score, vulnerabilities, README, dependency tree, version history) is being computed; this document will grow once it lands._

## Install

```sh
npm install @guardbee/mcp-tool-poisoning-scanner
pnpm add @guardbee/mcp-tool-poisoning-scanner
yarn add @guardbee/mcp-tool-poisoning-scanner
bun add @guardbee/mcp-tool-poisoning-scanner
```

## Facts

| | |
|---|---|
| Version | 0.1.0 |
| Published | 2026-09-24 |
| First published | 2026-09-24 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Dependencies | 3 |
| Unpacked size | 89.1 KB |
| Maintainers | guardbee.ai |
| Keywords | mcp, security, ai-security, mcp-security, tool-poisoning, prompt-injection, guardbee, devtools |

## Links

- npm: https://www.npmjs.com/package/@guardbee/mcp-tool-poisoning-scanner
- Repository: https://github.com/GuardBee/guardbee-mcp
- Homepage: https://github.com/GuardBee/guardbee-mcp#readme
- npm.io page: https://npm.io/package/@guardbee/mcp-tool-poisoning-scanner

---
_Source: https://npm.io/package/@guardbee/mcp-tool-poisoning-scanner · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
