tool-poisoning-scanner MCP Setup & Guide
io.github.GuardBee/tool-poisoning-scanner · v0.2.6
Scans MCP tool definitions for hidden instructions and confused-deputy sinks
Copy the install config on this page first, then verify docs and permissions upstream.
Overview
Scans MCP tool definitions for hidden instructions and confused-deputy sinks tool-poisoning-scanner is a MCP Server listed from MCP Registry. Transports: stdio. This page includes an overview, setup tutorial, install commands, and use cases for Trae, Tongyi Lingma, Cursor, Claude Code, and VS Code.
Use cases
AgentHub Verified AvailabilityTested & Ready
Automated pipeline validated install commands, protocol & client compatibility
Copy by platform
Choose your platform
- Open or create .cursor/mcp.json in your project root
- Click Copy config and paste; merge only this mcpServers entry if others exist
- Replace <placeholders> in env with real secrets (see Environment variables below)
- Save, then Cmd+Shift+P → Reload Window
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Setup tutorial
- Open the tool-poisoning-scanner page and confirm this MCP Server (source: MCP Registry).
- Copy the Cursor, Claude Code, or VS Code snippet.
- Merge it into mcpServers and replace env placeholders with real secrets.
- Reload the window, then call the MCP tools from your agent chat.
Install commands
Install commands and setup steps are in the HTML so search engines and no-JS browsers can read them without running client JavaScript.
Claude Code (local)
- Install Claude Code CLI
- Copy the command below, replace <placeholders> with real env values, then run in terminal
- See Environment variables below if listed
claude mcp add tool-poisoning-scanner -- npx -y @guardbee/mcp-tool-poisoning-scannerCursor — .cursor/mcp.json (local)
- Open or create .cursor/mcp.json in your project root
- Click Copy config and paste; merge only this mcpServers entry if others exist
- Replace <placeholders> in env with real secrets (see Environment variables below)
- Save, then Cmd+Shift+P → Reload Window
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}VS Code — .vscode/mcp.json (local)
- Install GitHub Copilot in VS Code with MCP support
- Open or create .vscode/mcp.json in your project root
- Click Copy config and paste; merge only this mcpServers entry if others exist
- Replace <placeholders> in env with real secrets
- Save and Developer: Reload Window
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Claude Desktop — claude_desktop_config.json (local)
- Open Claude Desktop claude_desktop_config.json (see remote guide for paths)
- Click Copy config and merge under mcpServers
- Replace <placeholders> in env with real secrets
- Fully quit and restart Claude Desktop
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Trae — .trae/mcp.json (local)
- Trae → Settings → MCP, or edit .trae/mcp.json / global mcp.json
- Click Copy config and merge mcpServers
- Replace <placeholders> in env with real secrets
- Save and reload Trae
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Cherry Studio — MCP settings (local)
- Cherry Studio → Settings → MCP Servers → Add (STDIO)
- Or import JSON: click Copy config and merge mcpServers
- Replace <placeholders> in env; ensure Node.js / uv (npx, uvx) are installed
- Enable the server and check tools load
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Tongyi Lingma — MCP config (local)
- Lingma Settings → MCP → + → STDIO or config file
- Click Copy config and merge mcpServers
- Replace <placeholders> in env; need Node.js 18+ (npx) or uv (uvx)
- Confirm connected before using tools in agent chat
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Windsurf — mcp_config.json (local)
- Edit ~/.codeium/windsurf/mcp_config.json
- Click Copy config and merge mcpServers (stdio same as Cursor)
- Replace <placeholders> in env, save, refresh Cascade
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Cline — MCP Servers (local)
- Cline panel → Settings → MCP Servers
- Click Copy config and merge
- Replace <placeholders> in env, then save
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}WorkBuddy — .workbuddy/mcp.json (local)
- Edit ~/.workbuddy/mcp.json (user) or project .workbuddy/mcp.json
- Or Plugins → MCP Servers → Configure MCP and paste the JSON below
- Replace <placeholders> in env; on Windows prefer absolute paths for command/scripts
- Save, restart WorkBuddy, confirm connector status is green
{
"mcpServers": {
"tool-poisoning-scanner": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-tool-poisoning-scanner"
]
}
}
}Troubleshooting & Common ErrorsFAQ
Common connection errors and verified fixes for tool-poisoning-scanner
Getting 'connection closed' or exit code 1 in Cursor / Claude Code for tool-poisoning-scanner?
Usually caused by missing runtime paths or IDE environment inheritance. Fix steps: 1. Verify Node.js 18+ (npx) or Python 3.10+ (uvx) is installed; 2. Run 'which npx' or 'which uvx' in terminal, and replace 'command' with absolute path; 3. Reload or restart the client window after modifying config.
# Check binary path in terminal: which npx node -v
Getting 'spawn npx ENOENT' or 'command not found'?
The editor background process does not inherit your full terminal PATH. Solution: Globally install the package, or set the absolute binary path (e.g. C:\Program Files\nodejs\npx.cmd on Windows, or /usr/local/bin/npx on macOS).
Tool calls timing out or failing to download packages?
First-time package downloading might be slow or timeout due to network limits. Configure a reliable mirror or check outbound proxy settings.
Tool Mock Playground
Sandboxtool-poisoning-scanner Tool Interface Simulation · Preview tool schema & outputs without local runtime
{
"target": "tool-poisoning-scanner",
"action": "execute",
"options": {
"mode": "standard",
"timeoutMs": 5000
}
}Click 'Run Mock' above
to preview the raw response returned to the LLM
Decision Guide: Why & When to Use
Assess suitability before installing to save trial-and-error time
- PR review
- Changelog generation
- Cross-repo issue search
- Replacing human security audit
- Unauthorized repo access
tool-poisoning-scanner + Scenario Prompt → Complete Agent Automation
MCP hands-on: install to visible results
Follow the full lab (expected UI/output + contrast checks). After installing this item, verify with the tutorial prompts.
Related resources
Kryptonian Labs XRPL APIs
v0.8.0
com.kriptonianlabs/xrpl
Read-only XRP Ledger data for agents: fees, order books, slippage, AMM pools, accounts and health.
Linkbreakers MCP
v1.158.2
com.linkbreakers/mcp
QR-driven customer-journey platform for tracked QR codes, short links, and analytics.
McpOrchestrator
v0.6.1
io.github.Byggarepop/dotnet-mcp-orchestrator
Route one agent through one MCP server to many, with progressive tool discovery to shrink context.
benethos-yahoo-finance-mcp
v0.8.4
io.github.benethos-hub/benethos-yahoo-finance-mcp
Unofficial read-only MCP server exposing Yahoo Finance data (via yfinance) over stdio or HTTP.
keryx
v0.4.15
io.github.tang-vu/keryx
Budgeted research with cited evidence and visible payment state on the selected Arc network.
Open Components
v1.0.0
com.uxfront/open-components
Guidelines for UI components with a perfect UX, DX and AX, whether humans or AI agents write them.
Often paired with
Planning with files
v3.23.0
io.clawhub.othmanadi/planning-with-files
Persistent file-based planning for multi-step AI-agent work. Keeps task_plan.md, findings.md, and progress.md on disk; lifecycle hooks inject selected project planning context. Automatic recovery reads project planning files only. Explicit session-catchup.py --metadata reads same-project local agent session records and emits aggregate counts only; --replay may emit bounded nonce-framed excerpts. Optional gated mode can request continuation only when the host supports it and never runs commands declared in Markdown. The skill has no network upload path. Use for research or work needing 5+ tool calls.
OpenClaw Command Center
v1.5.0
io.clawhub.jontsai/command-center
Mission control dashboard for OpenClaw - real-time session monitoring, LLM usage tracking, cost intelligence, and system vitals. View all your AI agents in one place.
ClawCall
v2.0.1
io.clawhub.clawcall-dev/clawcall-dev
Use when the user wants an AI agent to place a US phone call, call a business, handle hold or phone menus, confirm/reschedule/cancel/book/follow up/check an order, reach a real person, leave voicemail, connect the user into a live call, configure ClawCall voice/personality/profile or inbound reserved-number answering, poll received inbound calls, or link a ClawCall API key. Not for SMS, email, or international calls.
中文公文写作
v2.0.25
io.clawhub.gongyu0918-debug/chinese-official-writing
用于中文公文、事务性材料和新闻稿件的起草、改写、压缩、润色、审校、文种核对、去口语化、降 AI 味及 Word 格式处理,适用于机关、企事业单位、学校和新闻机构。涵盖申请、请示、报告、通知、通告、意见、决定、决议、议案、公报、命令、函、复函、批复、说明、方案、纪要、公告、公示、通报、制度、规定、办法、细则、操作规程、工作要点、总结、调研、讲话、致辞、主持词、述职、可研、审查材料、技术需求、新闻消息、编者按、新闻评论,以及采购、整改、反馈和 AI 算力等场景。
Keep exploring AgentHub
Most people compare similar tools or check scenario guides before installing—start here.
Listing badge: put AgentHub on your site
Copy either snippet into your project homepage, docs, or GitHub README. The badge is a hotlinked SVG — nothing to host — and it links back to this page so visitors can find the install steps.
<a href="https://myagenthub.cn/p/io.github.GuardBee/tool-poisoning-scanner" title="Listed on AgentHub: tool-poisoning-scanner" target="_blank" rel="noopener">
<img src="https://myagenthub.cn/badge/io.github.GuardBee/tool-poisoning-scanner?lang=en" alt="Listed on AgentHub: tool-poisoning-scanner" height="20" style="border:0"/>
</a>[](https://myagenthub.cn/p/io.github.GuardBee/tool-poisoning-scanner)Badges are generated on the fly from /badge/<package-id>, so name and listing changes propagate automatically. Keep the link target unchanged — it is what counts as the referral.
Unified Manifest
{
"id": "io.github.GuardBee/tool-poisoning-scanner",
"type": "mcp-server",
"version": "0.2.6",
"displayName": "tool-poisoning-scanner",
"description": "Scans MCP tool definitions for hidden instructions and confused-deputy sinks",
"repository": {
"url": "https://github.com/GuardBee/guardbee-mcp",
"source": "github",
"subfolder": "packages/tool-poisoning-scanner"
},
"distribution": {
"packages": [
{
"registryType": "npm",
"identifier": "@guardbee/mcp-tool-poisoning-scanner",
"version": "0.2.6",
"transport": "stdio"
}
],
"remotes": []
},
"dependencies": [],
"installTargets": [
"claude-code",
"claude-desktop",
"cursor",
"vscode",
"trae",
"cherry-studio",
"lingma",
"windsurf",
"cline",
"workbuddy"
],
"keywords": [],
"provenance": {
"origin": "official-mcp-registry",
"originalId": "io.github.GuardBee/tool-poisoning-scanner",
"originalUrl": "https://registry.modelcontextprotocol.io/v0.1/servers/io.github.GuardBee%2Ftool-poisoning-scanner/versions/latest",
"isOfficial": true,
"status": "active"
}
}