MCP server for InjectShield — prompt-injection firewall for AI agents. Wraps the InjectShield REST API as MCP tools for scanning text and URLs for prompt-injection attacks.
InjectShield MCP provides three well-named, security-focused tools with clear descriptions and complete input schemas. Tool names (scan, scan_url, patterns) follow verb_noun convention and are unambiguous. Descriptions are detailed (150-250 chars) and explain WHEN to use each tool. All parameters have types and descriptions. However, output schemas are not documented, LLMs cannot predict response structure for downstream chaining. Error handling guidance is absent. The patterns tool lacks parameter descriptions despite having an empty schema.
List supported threat categories, context kinds, and sensitivity levels. Use this to discover what threat_type values scan() can return.
Scan text for prompt-injection. Use BEFORE passing any untrusted text (web pages, file contents, user inputs, git commits, tool outputs) into another LLM call. Returns a verdict (safe/unsafe), a confidence score, the threat category, the matched pattern IDs, and an optional sanitized version with injection spans redacted.
Fetch a URL and scan its body for prompt-injection. Useful before feeding scraped page content into another LLM call. Sets the context to web_content automatically.
Output schemas not documented. LLMs cannot predict response structure (verdict, confidence, threat_category, pattern_ids, cleaned_text fields) for downstream tool chaining or result extraction.
patterns tool has empty input schema but no description of what it returns. LLMs cannot determine what fields or structure to expect from the discovery call.
No error handling guidance. If scan fails (e.g., API key missing, text too long, network error), LLMs receive no recovery hints. Descriptions should state 'Returns error if text exceeds 100,000 chars' and 'Requires INJECTSHIELD_API_KEY env var.'
scan_url max_bytes parameter (default 50000) lacks guidance on what happens if URL body exceeds limit. Is it truncated silently, or does the tool error? Ambiguity invites misuse.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
No mention of rate limits, API quotas, or cost implications. Agents may call scan repeatedly without understanding backend constraints or billing impact.