
Toxic Flow Auditor
io.github.GuardBeev0.1.14更新于 Oct 9, 2026
Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress
概览
审计 MCP 工具目录或服务器源码中的致命三要素风险流:不可信输入、敏感数据与外发。
- 功能
- 这个本地 MCP 服务器对工具目录或 MCP 服务器源码做静态分析,标出危险的能力组合。工具包括 audit_catalog(分析 tools/list 形式的 JSON 转储)、scan_source、scan_file 和 scan_directory(提取 .tool(...) 注册),以及 explain_trifecta(解释该模型)。它会报告致命三要素、单工具三要素,以及敏感+外发、不可信+破坏等危险组合,并给出 A-F 评级。仅做静态分析,不会调用实际工具。
- 适用场景
- 适合在审查或发布 MCP 服务器时使用,用来判断某个服务器是否同时具备获取不可信内容、访问敏感数据、以及外发或删除数据的能力。适用于安装前或发布前的工具目录与源码树审查,也包含土耳其 PII(KVKK)启发式规则。
- 运行要求
- 以本地 stdio 进程运行,从 npm 包 @guardbee/mcp-toxic-flow-auditor 安装,需要 Node.js。无需 API 密钥,未声明环境变量或请求头。也可通过 npx 使用命令行。除非关闭,否则会联网发送遥测。
安装
在 SourceWeft 中
- 打开 控制台中的 Toxic Flow Auditor,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
@guardbee/mcp-toxic-flow-auditor
🇬🇧 English | 🇹🇷 Türkçe | 🇨🇳 中文
An MCP server that audits an MCP tool catalog for toxic flows — Simon Willison's lethal trifecta:
- Untrusted content (fetch, scrape, browse, issues, feeds)
- Sensitive / private data (vault, DB, secrets, KVKK-regulated PII)
- Exfiltration or destruction (send, webhook, export, delete, drop)
When one MCP server exposes all three, a single prompt injection can chain them. Mapped primarily to OWASP MCP10:2025.
This package sends usage telemetry by default (tool name + short parameters, scanned code is never included — see
@guardbee/mcp-telemetry). Disable withGUARDBEE_TELEMETRY=0.
What it flags
- Lethal trifecta across the catalog. Tools that fetch untrusted content, reach vault/DB/PII, and can send data out or destroy it — on the same server.
- Single-tool trifecta. One registration whose name/description itself spans all three capabilities.
- Dangerous pairs. Sensitive+exfil, untrusted+exfil, or sensitive+destructive even when the full trifecta is not present.
- KVKK-aware heuristics. Turkish PII signals (
tc_kimlik,müşteri,KVKK) count as sensitive data. - snake_case names read word by word.
read_vault_secretanddrop_tableare classified by each word; opening a pull request counts as exfiltration.
Grades A–F. No API key. Static / catalog analysis only — does not call live tools.
The classification rules come from @guardbee/guard-core; @guardbee/mcp-security-proxy uses the same rules to block toxic flows at runtime.
Tools
CLI
Example catalog:
来源:packages/toxic-flow-auditor/README.md,提交 1a93a7c
工具
0版本历史
1- v0.1.14最新Oct 9, 2026


