OgunScan audits MCP server configurations for prompt injection, exposed credentials, and server-side vulnerabilities — in seconds.
Detects malicious instructions embedded in tool descriptions that hijack AI behavior.
Scans for hardcoded API keys, tokens, and secrets in env vars and command args.
Flags MCP servers using HTTP instead of HTTPS for remote connections.
Identifies ngrok tunnels, IP addresses, free-TLD domains, and Tor services.
Warns on overly-permissive scopes like shell_exec, file_write, and admin.
Detects unpinned npx/uvx packages vulnerable to dependency hijacking attacks.