Toxic Flow Auditor

io.github.GuardBeev0.1.14更新于 Oct 9, 2026

Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress

概览

AI 生成的概览

审计 MCP 工具目录或服务器源码中的致命三要素风险流:不可信输入、敏感数据与外发。

功能
这个本地 MCP 服务器对工具目录或 MCP 服务器源码做静态分析,标出危险的能力组合。工具包括 audit_catalog(分析 tools/list 形式的 JSON 转储)、scan_source、scan_file 和 scan_directory(提取 .tool(...) 注册),以及 explain_trifecta(解释该模型)。它会报告致命三要素、单工具三要素,以及敏感+外发、不可信+破坏等危险组合,并给出 A-F 评级。仅做静态分析,不会调用实际工具。
适用场景
适合在审查或发布 MCP 服务器时使用,用来判断某个服务器是否同时具备获取不可信内容、访问敏感数据、以及外发或删除数据的能力。适用于安装前或发布前的工具目录与源码树审查,也包含土耳其 PII(KVKK)启发式规则。
运行要求
以本地 stdio 进程运行,从 npm 包 @guardbee/mcp-toxic-flow-auditor 安装,需要 Node.js。无需 API 密钥,未声明环境变量或请求头。也可通过 npx 使用命令行。除非关闭,否则会联网发送遥测。
安装前请注意
该包默认发送使用遥测(工具名与简短参数,不包含被扫描的代码),可用 GUARDBEE_TELEMETRY=0 关闭。它只读取目录与源码文本,不调用实际工具,因此结论属于启发式判断,可能对名称产生误判。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Toxic Flow Auditor,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

@guardbee/mcp-toxic-flow-auditor

🇬🇧 English | 🇹🇷 Türkçe | 🇨🇳 中文

An MCP server that audits an MCP tool catalog for toxic flows — Simon Willison's lethal trifecta:

  1. Untrusted content (fetch, scrape, browse, issues, feeds)
  2. Sensitive / private data (vault, DB, secrets, KVKK-regulated PII)
  3. Exfiltration or destruction (send, webhook, export, delete, drop)

When one MCP server exposes all three, a single prompt injection can chain them. Mapped primarily to OWASP MCP10:2025.

This package sends usage telemetry by default (tool name + short parameters, scanned code is never included — see @guardbee/mcp-telemetry). Disable with GUARDBEE_TELEMETRY=0.

Claude ──► toxic-flow-auditor ──► tools/list JSON or MCP server source              │              ├─ lethal_trifecta      (untrusted + sensitive + outbound)              ├─ single_tool_trifecta (one tool alone spans all three)              ├─ sensitive_plus_exfil              ├─ untrusted_plus_exfil              └─ sensitive_plus_destruct

What it flags

  • Lethal trifecta across the catalog. Tools that fetch untrusted content, reach vault/DB/PII, and can send data out or destroy it — on the same server.
  • Single-tool trifecta. One registration whose name/description itself spans all three capabilities.
  • Dangerous pairs. Sensitive+exfil, untrusted+exfil, or sensitive+destructive even when the full trifecta is not present.
  • KVKK-aware heuristics. Turkish PII signals (tc_kimlik, müşteri, KVKK) count as sensitive data.
  • snake_case names read word by word. read_vault_secret and drop_table are classified by each word; opening a pull request counts as exfiltration.

Grades A–F. No API key. Static / catalog analysis only — does not call live tools.

The classification rules come from @guardbee/guard-core; @guardbee/mcp-security-proxy uses the same rules to block toxic flows at runtime.

Tools

ToolPurpose
audit_catalogAudit a tools/list-shaped JSON dump
scan_sourceExtract .tool(...) registrations from source text
scan_fileScan one source file
scan_directoryRecursive scan; merges tools across files
explain_trifectaExplain the model

CLI

npx @guardbee/mcp-toxic-flow-auditor audit <tools.json> [--fail-on=any] [--format=text|json|sarif]npx @guardbee/mcp-toxic-flow-auditor scan <path>        [--fail-on=any] [--format=text|json|sarif]

Example catalog:

json
{  "tools": [    { "name": "fetch_page", "description": "Scrape a URL" },    { "name": "read_vault_secret", "description": "Read API key from vault" },    { "name": "send_slack_message", "description": "Post to webhook" }  ]}

来源:packages/toxic-flow-auditor/README.md,提交 1a93a7c

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.14最新Oct 9, 2026