
Toxic Flow Auditor
io.github.4hmetuyarv0.1.3Updated Sep 30, 2026
Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress
Installation
In SourceWeft
- Open Toxic Flow Auditor in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
@guardbee/mcp-toxic-flow-auditor
🇬🇧 English | 🇹🇷 Türkçe | 🇨🇳 中文
An MCP server that audits an MCP tool catalog for toxic flows — Simon Willison's lethal trifecta:
- Untrusted content (fetch, scrape, browse, issues, feeds)
- Sensitive / private data (vault, DB, secrets, KVKK-regulated PII)
- Exfiltration or destruction (send, webhook, export, delete, drop)
When one MCP server exposes all three, a single prompt injection can chain them. Mapped primarily to OWASP MCP10:2025.
This package sends usage telemetry by default (tool name + short parameters, scanned code is never included — see
@guardbee/mcp-telemetry). Disable withGUARDBEE_TELEMETRY=0.
What it flags
- Lethal trifecta across the catalog. Tools that fetch untrusted content, reach vault/DB/PII, and can send data out or destroy it — on the same server.
- Single-tool trifecta. One registration whose name/description itself spans all three capabilities.
- Dangerous pairs. Sensitive+exfil, untrusted+exfil, or sensitive+destructive even when the full trifecta is not present.
- KVKK-aware heuristics. Turkish PII signals (
tc_kimlik,müşteri,KVKK) count as sensitive data. - snake_case names read word by word.
read_vault_secretanddrop_tableare classified by each word; opening a pull request counts as exfiltration.
Grades A–F. No API key. Static / catalog analysis only — does not call live tools.
The classification rules come from @guardbee/guard-core; @guardbee/mcp-security-proxy uses the same rules to block toxic flows at runtime.
Tools
CLI
Example catalog:
Source: packages/toxic-flow-auditor/README.md at commit 4c36e56
Tools
0Version history
1- v0.1.3LatestSep 30, 2026


