Toxic Flow Auditor

io.github.GuardBeev0.1.14Updated Oct 9, 2026

Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Audits an MCP tool catalog or server source for lethal-trifecta toxic flows combining untrusted input, sensitive data, and egress.

What it does
This local MCP server statically analyzes a tool catalog or MCP server source code and flags dangerous capability combinations. Tools include audit_catalog for a tools/list-shaped JSON dump, scan_source, scan_file, and scan_directory for extracting .tool(...) registrations, and explain_trifecta for the model itself. It reports lethal trifecta, single-tool trifecta, and dangerous pairs such as sensitive+exfil or untrusted+destruct, with A-F grades. Analysis is static only; it does not call live tools.
When to use it
Use it when reviewing or shipping an MCP server and you want to know whether one server combines fetching untrusted content, reaching sensitive data, and sending data out or deleting it. It suits pre-install or pre-release review of tool catalogs and source trees, including Turkish PII (KVKK) heuristics.
Requirements
Runs as a local stdio process, installed from the npm package @guardbee/mcp-toxic-flow-auditor; Node.js is needed. No API key and no declared environment variables or headers. A CLI is also available via npx. Network access is used for telemetry unless disabled.
Before you install
The package sends usage telemetry by default (tool name and short parameters; scanned code is not included) and can be disabled with GUARDBEE_TELEMETRY=0. It only reads catalogs and source text and does not call live tools, so findings are heuristic and may misclassify names.

Installation

In SourceWeft

  1. Open Toxic Flow Auditor in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

@guardbee/mcp-toxic-flow-auditor

🇬🇧 English | 🇹🇷 Türkçe | 🇨🇳 中文

An MCP server that audits an MCP tool catalog for toxic flows — Simon Willison's lethal trifecta:

  1. Untrusted content (fetch, scrape, browse, issues, feeds)
  2. Sensitive / private data (vault, DB, secrets, KVKK-regulated PII)
  3. Exfiltration or destruction (send, webhook, export, delete, drop)

When one MCP server exposes all three, a single prompt injection can chain them. Mapped primarily to OWASP MCP10:2025.

This package sends usage telemetry by default (tool name + short parameters, scanned code is never included — see @guardbee/mcp-telemetry). Disable with GUARDBEE_TELEMETRY=0.

Claude ──► toxic-flow-auditor ──► tools/list JSON or MCP server source              │              ├─ lethal_trifecta      (untrusted + sensitive + outbound)              ├─ single_tool_trifecta (one tool alone spans all three)              ├─ sensitive_plus_exfil              ├─ untrusted_plus_exfil              └─ sensitive_plus_destruct

What it flags

  • Lethal trifecta across the catalog. Tools that fetch untrusted content, reach vault/DB/PII, and can send data out or destroy it — on the same server.
  • Single-tool trifecta. One registration whose name/description itself spans all three capabilities.
  • Dangerous pairs. Sensitive+exfil, untrusted+exfil, or sensitive+destructive even when the full trifecta is not present.
  • KVKK-aware heuristics. Turkish PII signals (tc_kimlik, müşteri, KVKK) count as sensitive data.
  • snake_case names read word by word. read_vault_secret and drop_table are classified by each word; opening a pull request counts as exfiltration.

Grades A–F. No API key. Static / catalog analysis only — does not call live tools.

The classification rules come from @guardbee/guard-core; @guardbee/mcp-security-proxy uses the same rules to block toxic flows at runtime.

Tools

ToolPurpose
audit_catalogAudit a tools/list-shaped JSON dump
scan_sourceExtract .tool(...) registrations from source text
scan_fileScan one source file
scan_directoryRecursive scan; merges tools across files
explain_trifectaExplain the model

CLI

npx @guardbee/mcp-toxic-flow-auditor audit <tools.json> [--fail-on=any] [--format=text|json|sarif]npx @guardbee/mcp-toxic-flow-auditor scan <path>        [--fail-on=any] [--format=text|json|sarif]

Example catalog:

json
{  "tools": [    { "name": "fetch_page", "description": "Scrape a URL" },    { "name": "read_vault_secret", "description": "Read API key from vault" },    { "name": "send_slack_message", "description": "Post to webhook" }  ]}

Source: packages/toxic-flow-auditor/README.md at commit 1a93a7c

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.14LatestOct 9, 2026