Audita tu Agente y Servidor MCP
Simula inyecciones adversariales reales, detecta envenenamiento de tools y verifica cumplimiento de protocolos. Obtén tu puntuación y un prompt de 1 clic para blindar tu código en Cursor, Claude Code u OpenCode.
Elevated Risk
Audit flagged 1 vulnerabilities against the Galvanize-60M benchmark.
ev_26caa5717b2f8a9cDESGLOSE POR PILARES DE SEGURIDAD (BENCHMARK GALVANIZE)
CHECKLIST DE AUDITORÍA (12 CHECKS VERIFICADOS)
Audit against adversarial instruction overrides and boundary escape markers ([SYSTEM], <<SYS>>, <im_start>).
Evaluates resilience against multi-token indirect injections hidden in retrieved documents and tool outputs.
import { withZnGateway } from '@usezn/gateway';
// Blindaje automático en 12ms con Galvanize-60MNeutraliza la inyección indirecta (OWASP-LLM01) y el tool poisoning (OWASP-LLM02) en línea en el bucle de tu agente con el gateway Galvanize-60M.
Activar Gateway de Producción · Plan de prueba gratuito incluidoVerifies the agent refuses imperatives commanding it to leak system prompts, API keys, or memory records.
Ensures all tool parameters define explicit primitive types, bounds, and reject unconstrained open objects.
Scans tool descriptions and metadata for embedded prompt injection vectors and planner coercion attacks.
Prevents adversarial context from redefining, shadowing, or overriding system tool definitions.
Flags tools providing unconstrained bash, powershell, or eval access on host environments (OWASP LLM08).
Verifies file operations are strictly scoped to isolated directory sandboxes without write traversal.
Verifies that API keys, passwords, and tokens are injected at gateway layer, never as model parameters.
Validates that agent endpoints and MCP transport connections enforce HTTPS encryption in transit.
Checks for standard Authorization headers and OAuth 2.1 RFC token verification on MCP endpoints.
Requires explicit human approval workflows before executing irreversible financial or account mutations.
Leaderboard Público de Seguridad de Servidores MCP
Calificaciones de seguridad verificadas en los servidores Model Context Protocol más adoptados.
| Puesto | Servidor / Objetivo | Puntuación | Nota | Acción |
|---|---|---|---|---|
| #1 | zn-Hardened Enterprise Gateway zn-hardened-gateway · Gateway | 100/100 | A+ | |
| #2 | GitHub Copilot Workspace Agent github.com/github/copilot-agent · Developer Tools | 91/100 | A | |
| #3 | Model Context Protocol (Official Reference) modelcontextprotocol.io · Core Protocol | 90/100 | A | |
| #4 | PostgreSQL MCP Server modelcontextprotocol/servers/postgres · Database | 88/100 | A | |
| #5 | Brave Search MCP Server modelcontextprotocol/servers/brave-search · Search & Web | 86/100 | A | |
| #6 | AWS Cloud MCP Server aws.amazon.com/mcp/cloud · Cloud Infrastructure | 85/100 | A | |
| #7 | Google Drive MCP Server mcp.google.com/drive · Collaboration | 84/100 | B | |
| #8 | Redis MCP Server github.com/redis/mcp-redis · Database | 84/100 | B | |
| #9 | Notion MCP Server mcp.notion.com · Collaboration | 83/100 | B | |
| #10 | Sentry Error Tracking MCP mcp.sentry.dev · Observability | 83/100 | B | |
| #11 | Slack MCP Server modelcontextprotocol/servers/slack · Collaboration | 82/100 | B | |
| #12 | Kubernetes Cluster MCP mcp.kubernetes.io · Cloud Infrastructure | 80/100 | B | |
| #13 | Docker Container MCP mcp.docker.com · Containers | 79/100 | B | |
| #14 | SQLite Local MCP sqlite.local · Database | 78/100 | B | |
| #15 | Git Version Control MCP git-mcp.dev · Developer Tools | 76/100 | B | |
| #16 | Puppeteer Browser MCP mcp.puppeteer.dev · Browser Automation | 75/100 | B | |
| #17 | Filesystem Scoped MCP modelcontextprotocol/servers/filesystem · System & FS | 74/100 | B | |
| #18 | Fetch Web Scraping MCP mcp.fetch.dev · Search & Web | 71/100 | B | |
| #19 | Discord Community MCP mcp.discord.dev · Community | 68/100 | C | |
| #20 | Unrestricted Shell Agent Legacy legacy-open-interpreter.local · Legacy OS Agent | 66/100 | C |
Muestra tu calificación verificada en GitHub
Incrusta este badge dinámico en el README.md de tu repositorio para certificar la seguridad de tu agente.
[-red?style=flat-square&logo=shield)](https://usezn.com/scan/)Protege tu Agente IA con Galvanize-60M en 1 Línea
Defensa sacrificial contra inyecciones de prompt, infilling y envenenamiento de herramientas. Inferencia sub-15ms en CPU con cero retención de datos.