mcp.json or claude_desktop_config.json
a tools/list response
🔒 Runs in your browser. Nothing you paste is uploaded.
+What it checks
The setup-time checks we run in the product
Servers
- stdio commands that download and run code (curl | sh, bash -c, eval)
- Upstreams pointing at private, loopback or cloud-metadata addresses
- Plaintext API keys and tokens in the config
- Unknown remote servers with nothing pinned
Tools
- Instructions addressed to the model, including 'don't tell the user'
- Invisible characters that hide text from reviewers
- References to credential and config files
- Known hidden-instruction patterns
This is the setup-time check only. In production, MCP Guard also pins each server's tool list, detects drift, and authorizes every tools/call with its real arguments. How MCP Guard works →
+ The AI watching your AI
Keep every MCP call in check.
Route MCP through Intertrace and every tool call is authorized before it runs.