Security scanner for MCP servers and AI agent skills. Scan before you install.
acidtest is a security scanner tool for MCP servers and agent skills. It exposes 3 tools with well-defined purposes, clear action-verb naming (scan_*, lint_*), and comprehensive descriptions. All tools have proper input schemas with typed parameters. However, output schemas are not documented in the visible source code, and tool annotations (readOnlyHint) are missing despite all tools being read-only operations. The descriptions are strong (170-250 chars, well above the 10-char minimum and within the 194-char baseline average), and parameter descriptions are present. Error handling and recovery guidance are not visible in the tool definitions themselves.
Lint an MCP server's own tool descriptions before publishing. Checks the manifest and the description strings in TypeScript/JavaScript/Python source for injected instructions, hidden emphasis tags, concealment directives, covert parameters, and cross-server shadowing. Returns located findings (file, line, rule, severity) — the same things a consumer's security scanner would flag. Designed for precision: it stays quiet on legitimate wording.
Recursively scan all skills and MCP servers in a directory. Returns an array of scan results with trust scores and findings for each skill/server found.
Scan an AI agent skill or MCP server for security vulnerabilities. Returns a trust score (0-100) and findings from two analysis layers: an injection scan of tool descriptions, manifests, and markdown (prompt injection, tool poisoning, cross-server shadowing, credential exfil, invisible-Unicode) and a code scan (dangerous imports/sinks, obfuscation, credentials) of TypeScript/JavaScript/Python source.
Output schemas not documented. Tool descriptions explain findings return structure but do not formally specify JSON schema for responses. LLMs cannot plan downstream processing or validate returned fields.
Missing tool annotations. All three tools are read-only (Risk: READ_ONLY declared) but MCP tool definitions lack readOnlyHint annotation. This prevents clients from optimizing permissions, caching, or parallelization.
Error handling guidance missing from tool definitions. Descriptions do not explain what errors might occur (e.g., invalid path, permission denied, unsupported file format) or how the agent should recover. No actionable error messages visible in schema.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 65 | 2026-07-28+ | v2 |
STDIO transport only. Server is not remotely accessible and cannot be used by hosted MCP clients. Limits deployment to local environments.