Security scanner for Model Context Protocol (MCP) servers and AI agent skills (Claude Code commands, agentskills.io bundles, Cursor / Codex / Windsurf / Gemini equivalents).
Ramparts provides two security scanning tools with complete input schemas and reasonable descriptions. Both tools follow verb-noun naming (scan, scan-config) and include comprehensive parameter documentation. However, descriptions lack LLM-optimized detail about WHEN to use each tool vs. the other, output schemas are not explicitly documented, and error handling/recovery guidance is absent. The server demonstrates solid foundation-level work but misses production-grade polish expected for security-critical tools.
Scan an MCP server URL and return security findings as JSON
Scan MCP servers from IDE configuration files and return results as JSON
Output schemas are not documented. Both tools claim to return 'security findings as JSON' but the response structure is not specified. LLMs cannot plan downstream data extraction or chain results to other tools without knowing field names, types, and nesting.
Ambiguous tool naming and descriptions. Both tools scan MCP servers but the distinction is unclear: 'scan' vs. 'scan-config' sounds like two ways to do the same thing. Descriptions do not explain WHEN to call each. LLMs may pick the wrong tool or call both redundantly.
Missing error handling and recovery guidance. No documentation of what errors the tools can return, which are retryable, or what the LLM should do if scan fails (e.g., 'URL unreachable, verify network access and try again' vs. 'MCP server returned invalid response, check server logs').
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 68 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 43 | 2024-11-05+ | v1 |
Parameter 'returnPrompts' defaults to true on both tools, which is non-standard and confusing. A parameter named 'returnPrompts' with default true suggests the tool returns prompts instead of calling an LLM, but the description and tool purpose are unclear about this mode. This creates ambiguity: does the LLM always run? Only when returnPrompts=false?
Missing pagination/limits documentation. No indication whether results are capped, paginated, or can grow unbounded. If scanning returns thousands of findings, the response could exhaust context windows. Baseline pattern expects explicit limits and pagination.
Descriptions lack LLM-optimized context. They should include: what the tool does, when to use it, any prerequisites, and what happens. Current descriptions are technical but lack actionable context for LLM selection.