MCP toolguard
Contracts, drift and security for MCP servers — in CI and in production.
No signup · 30 seconds · or in your terminal: uvx mcp-toolguard scan <target>
A silent rename. All your agents broken.
An MCP server can change its contract on any deploy. It breaks no build and trips no type-checker: it breaks your agents in production, silently.
- 1The server ships v2.5.0:
querybecomessearch_query. Nobody announces it. - 2Your agents keep calling with
query. Every invocation fails. You find out from your users. - 3With ToolGuard on the PR, the breaking change is visible, discussed and blocked before the merge.
Contracts, drift and security.
One single engine.
The contract lives in your repo
A canonical snapshot of tools, schemas and capabilities. Validated against the spec matrix: the current version and 2026-07-28.
Every change, classified
Breaking, compatible or suspicious. In CI through the Action; in production through scheduled checks and alerts.
Tool poisoning, watched
15 rules against injection and exfiltration. The baseline is the accepted state: only new findings block.
Everything it watches, explained.
The same engine, layer by layer: what it captures, what it compares and what it blocks.
Your server's contract, committed
A canonical snapshot of tools, schemas, capabilities and instructions, with a deterministic hash. It lives in .toolguard/baseline.json, versioned with your code: the contract gets reviewed where everything else does — in the PR.
Every change gets a surname
Not a text diff — a semantic diff of the contract. Removals and type changes are breaking; additions are compatible; and text that reaches the model's context — descriptions, instructions — is flagged suspicious: that is the prompt-injection surface.
15 rules against tool poisoning
Imperative instructions to the model, hidden tags, cross-tool coercion, credential-shaped parameters, invisible characters. Every finding ships its evidence — and the baseline is the accepted state: only new findings block your CI.
Ready for 2026-07-28 before July 28
Every snapshot is validated against two MCP spec versions at once: the current one and the next. One independent report per version — you know today exactly what breaks tomorrow.
Once deployed, we keep watching
Scheduled checks against your servers — and the third-party ones you depend on. If the contract shifts under your feet, the alert reaches you in minutes, not when your agents start failing.
Two snippets. Zero infrastructure.
- Pass/fail check + a single self-updating PR comment.
- The baseline lives in your repo: the free tier works 100 % offline.
- Accepting a breaking change is a visible commit in review.
- Open source, MIT —
pip install mcp-toolguard
Transparent. Self-service.
No “book a demo”.
The unit of value is the monitored server. Unlimited seats on every paid plan: alerts must reach the whole on-call rotation.
To try it out, and for any repo's CI. 100 % offline.
- 1 monitored server
- Daily check
- 7-day history
- Email alerts
- Basic findings on scan
- README badge
For anyone publishing or seriously depending on MCP servers.
- 5 monitored servers
- Check every 15 min
- 90-day history
- + Slack and webhooks
- Continuous security rules
- CI ↔ production correlation
For teams with server fleets and on-call rotations.
- 25 monitored servers
- Check every 5 min
- 1-year history
- + severity-based alert routing
- + OWASP report with trends
- Per-environment baselines
Custom: large fleets, compliance, on-prem.
- Custom servers and frequency
- + PagerDuty, SIEM
- + custom rules, evidence export
- Multi-org
- SSO/SAML
Annual: 2 months free · USD, automatic tax · cancel anytime