Deepsleuth
io.github.DeepSleuthv1.0.3更新于 Oct 6, 2026
Deterministic, no-LLM security scanner for MCP servers, plus an inline proxy gate.
概览
一个确定性的、不使用 LLM 的 MCP 服务器安全扫描器,可审计清单、源码、运行时响应和安装钩子,并能作为内联代理网关。
- 功能
- Deepsleuth 在不使用 LLM 的情况下扫描 MCP 服务器的安全问题,相同输入会产生逐字节一致的发现结果。它提供两种前端:内联 MCP 网关/代理,在启动时审计工具描述、在每次 tools/call 前执行门禁,并在返回前扫描响应;以及批处理/沙箱扫描器,在 Docker 中启动服务器,用合成调用和植入的金丝雀主动诱发行为。它暴露 MCP 工具 list_detectors、check_listing 和 scan_target,覆盖的证据位置包括描述、源码、运行时响应、多次调用状态、服务器身份和安装时脚本。
- 适用场景
- 当你希望在信任某个 MCP 服务器之前对其进行审查,或希望在助手调用的服务器前加一道运行时门禁时使用。它面向 MCP 服务器的安全审查,而非通用扫描。
- 运行要求
- 需要 Python 3.11+ 和 PyPI 包 deepsleuth,或源码仓库;没有必需的第三方依赖。动态层和 proxy-eval 需要 Docker CLI 与守护进程;没有 Docker 时静态和清单检测器仍会运行,并会报告被跳过的动态覆盖。通过 stdio 在本地运行;未声明认证或环境变量。
安装
在 SourceWeft 中
- 打开 控制台中的 Deepsleuth,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Deepsleuth — read the fine print
Deepsleuth is a deterministic, no-LLM security scanner for MCP servers. It audits what a server says — and, more importantly, what it does.
Most MCP scanners read only the declared manifest (tools/list names,
descriptions, schemas). They never launch the server, never call a tool, never
read a response, never read the implementation source, and never reason across
calls — so whole classes of attack are structurally invisible to them.
Deepsleuth sees those. It is a single frontend-agnostic detection core with two frontends:
- Frontend A — inline MCP gateway / proxy (the headline artifact). A
transparent proxy that is an MCP server to the agent and an MCP client to one
downstream server. It audits tool descriptions at startup, enforces a gate
before every
tools/call, and scans every response before returning it. Includes a headlessproxy-evalmode for offline scoring. - Frontend B — batch / sandbox scanner. A pre-flight auditor that launches a server in a Docker sandbox, actively elicits behavior with synthesized calls + planted canaries, and produces findings. Also the offline scoring harness.
Both frontends run the same detectors over the same Context — a detector is
written once and works in both.
No LLM. Ever.
Fully deterministic: parsing, static AST + taint/dataflow, normalized regex/token heuristics, unicode/encoding/entropy analysis, structural diffing, and sandboxed dynamic execution with instrumentation. Same input → byte-identical findings. Offline (no network egress except to the Docker daemon). No threat feeds.
Install
Python 3.11+. No required third-party packages — the scanner speaks MCP over stdio itself, so it installs in externally-managed (PEP 668) environments.
Deepsleuth is itself an MCP server, so agents can scan with it directly:
Tools: list_detectors, check_listing, scan_target.
Install as an agent plugin
The repo is a valid Agent Plugins package
(plugin.json + mcp.json, spec 1.0.0): any compatible client can install it
directly from the repository and gets the deepsleuth MCP server plus the
audit-mcp-server skill. The stdio entry (bin/deepsleuth-mcp) needs only
python3.11+ — the scanner has zero third-party requirements:
For the dynamic layer (Frontend B and proxy-eval) you need the Docker CLI +
daemon. Without Docker the scanner degrades gracefully: static/manifest
detectors still run and the skipped dynamic coverage is reported (never a crash).
Run
<target> can be a server directory (with mcp.json and/or source), an
mcp.json launch spec, or a raw stdio launch command (e.g.
"python3 server.py"). scan exits 0 when clean and non-zero once a finding
reaches --fail-severity (default high).
--allow-unsandboxed runs the dynamic layer without Docker — use it only
for your own trusted fixtures, never on untrusted servers.
--reference-listing tools.json supplies another server's tool list (a JSON
array of {name, description, inputSchema} entries, or an object with a
tools key) so the cross-server name comparison runs against it without
launching a second server. The same comparison also runs automatically across
several entries in one mcp.json and across several server entry modules
found in one directory.
Wire the proxy into an agent
Point your MCP client at the proxy instead of the real server; the proxy launches the real one downstream:
Try it on the bundled fixtures
What it covers
Evidence locations — deepsleuth detects across all eight, with special strength on the five a manifest-only scanner misses:
Mechanism categories: tool-poisoning, agent-config-poisoning,
tool-shadowing, prompt-injection, credential-exposure, command-injection,
path-traversal, ssrf, data-exfiltration, confused-deputy,
auth-misconfiguration, denial-of-service, excessive-privilege,
supply-chain, information-disclosure, client-side-vulnerability, other.
Every finding validates against the fixed finding schema, carries a top-level
evidence_location and confidence, and (from the proxy) records its gate
decision on raw.gate_decision. See DETECTORS.md for one entry per detector
including its known blind spots, and ARCHITECTURE.md for how the layers fit
and how to add a detector.
Known limitations (v1)
- Source analysis is Python-first. Node/TS servers get manifest + install-hook
- dynamic coverage, but source taint is Python-only in v1 (JS is regex-lite).
- Taint is intra-procedural. Flows through helper functions/classes across the module are approximated, not fully tracked.
- The proxy fronts exactly one downstream server (v1 scope; multi-server namespacing is structured for but not built).
- The live proxy's elicitation round-trip and forwarding of downstream-initiated
requests are best-effort. All gate/audit/diff/response logic is fully exercised
by
proxy-eval, which is what the offline evaluator scores. - Without Docker, dynamic detectors are skipped (reported, not silent).
Getting involved
Contributions welcome — see CONTRIBUTING.md. Found a security issue? Please follow SECURITY.md.
Listed in the official MCP Registry:
mcp-name: io.github.DeepSleuth/deepsleuth
来源:README.md,提交 a73c55c
工具
0版本历史
1- v1.0.3最新Oct 6, 2026


