
Toxic Flow Auditor
io.github.GuardBeev0.1.14Updated Oct 9, 2026
Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress
Overview
Audits an MCP tool catalog or server source for lethal-trifecta toxic flows combining untrusted input, sensitive data, and egress.
- What it does
- This local MCP server statically analyzes a tool catalog or MCP server source code and flags dangerous capability combinations. Tools include audit_catalog for a tools/list-shaped JSON dump, scan_source, scan_file, and scan_directory for extracting .tool(...) registrations, and explain_trifecta for the model itself. It reports lethal trifecta, single-tool trifecta, and dangerous pairs such as sensitive+exfil or untrusted+destruct, with A-F grades. Analysis is static only; it does not call live tools.
- When to use it
- Use it when reviewing or shipping an MCP server and you want to know whether one server combines fetching untrusted content, reaching sensitive data, and sending data out or deleting it. It suits pre-install or pre-release review of tool catalogs and source trees, including Turkish PII (KVKK) heuristics.
- Requirements
- Runs as a local stdio process, installed from the npm package @guardbee/mcp-toxic-flow-auditor; Node.js is needed. No API key and no declared environment variables or headers. A CLI is also available via npx. Network access is used for telemetry unless disabled.
Installation
In SourceWeft
- Open Toxic Flow Auditor in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
@guardbee/mcp-toxic-flow-auditor
🇬🇧 English | 🇹🇷 Türkçe | 🇨🇳 中文
An MCP server that audits an MCP tool catalog for toxic flows — Simon Willison's lethal trifecta:
- Untrusted content (fetch, scrape, browse, issues, feeds)
- Sensitive / private data (vault, DB, secrets, KVKK-regulated PII)
- Exfiltration or destruction (send, webhook, export, delete, drop)
When one MCP server exposes all three, a single prompt injection can chain them. Mapped primarily to OWASP MCP10:2025.
This package sends usage telemetry by default (tool name + short parameters, scanned code is never included — see
@guardbee/mcp-telemetry). Disable withGUARDBEE_TELEMETRY=0.
What it flags
- Lethal trifecta across the catalog. Tools that fetch untrusted content, reach vault/DB/PII, and can send data out or destroy it — on the same server.
- Single-tool trifecta. One registration whose name/description itself spans all three capabilities.
- Dangerous pairs. Sensitive+exfil, untrusted+exfil, or sensitive+destructive even when the full trifecta is not present.
- KVKK-aware heuristics. Turkish PII signals (
tc_kimlik,müşteri,KVKK) count as sensitive data. - snake_case names read word by word.
read_vault_secretanddrop_tableare classified by each word; opening a pull request counts as exfiltration.
Grades A–F. No API key. Static / catalog analysis only — does not call live tools.
The classification rules come from @guardbee/guard-core; @guardbee/mcp-security-proxy uses the same rules to block toxic flows at runtime.
Tools
CLI
Example catalog:
Source: packages/toxic-flow-auditor/README.md at commit 1a93a7c
Tools
0Version history
1- v0.1.14LatestOct 9, 2026


