
Toxic Flow Auditor
io.github.GuardBeev0.1.14更新於 Oct 9, 2026
Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress
概覽
稽核 MCP 工具目錄或伺服器原始碼中的致命三要素風險流:不受信任輸入、敏感資料與外送。
- 功能
- 這個本機 MCP 伺服器會對工具目錄或 MCP 伺服器原始碼做靜態分析,標出危險的能力組合。工具包括 audit_catalog(分析 tools/list 形式的 JSON 傾印)、scan_source、scan_file 與 scan_directory(擷取 .tool(...) 註冊),以及 explain_trifecta(說明此模型)。它會回報致命三要素、單一工具三要素,以及敏感+外送、不受信任+破壞等危險組合,並給出 A-F 評級。僅做靜態分析,不會呼叫實際工具。
- 適用情境
- 適合在審查或發佈 MCP 伺服器時使用,用來判斷某個伺服器是否同時具備取得不受信任內容、存取敏感資料,以及外送或刪除資料的能力。適用於安裝前或發佈前的工具目錄與原始碼樹審查,也包含土耳其 PII(KVKK)啟發式規則。
- 執行需求
- 以本機 stdio 程序執行,從 npm 套件 @guardbee/mcp-toxic-flow-auditor 安裝,需要 Node.js。不需要 API 金鑰,未宣告環境變數或標頭。也可透過 npx 使用命令列。除非關閉,否則會連線傳送遙測。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Toxic Flow Auditor,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
@guardbee/mcp-toxic-flow-auditor
🇬🇧 English | 🇹🇷 Türkçe | 🇨🇳 中文
An MCP server that audits an MCP tool catalog for toxic flows — Simon Willison's lethal trifecta:
- Untrusted content (fetch, scrape, browse, issues, feeds)
- Sensitive / private data (vault, DB, secrets, KVKK-regulated PII)
- Exfiltration or destruction (send, webhook, export, delete, drop)
When one MCP server exposes all three, a single prompt injection can chain them. Mapped primarily to OWASP MCP10:2025.
This package sends usage telemetry by default (tool name + short parameters, scanned code is never included — see
@guardbee/mcp-telemetry). Disable withGUARDBEE_TELEMETRY=0.
What it flags
- Lethal trifecta across the catalog. Tools that fetch untrusted content, reach vault/DB/PII, and can send data out or destroy it — on the same server.
- Single-tool trifecta. One registration whose name/description itself spans all three capabilities.
- Dangerous pairs. Sensitive+exfil, untrusted+exfil, or sensitive+destructive even when the full trifecta is not present.
- KVKK-aware heuristics. Turkish PII signals (
tc_kimlik,müşteri,KVKK) count as sensitive data. - snake_case names read word by word.
read_vault_secretanddrop_tableare classified by each word; opening a pull request counts as exfiltration.
Grades A–F. No API key. Static / catalog analysis only — does not call live tools.
The classification rules come from @guardbee/guard-core; @guardbee/mcp-security-proxy uses the same rules to block toxic flows at runtime.
Tools
CLI
Example catalog:
來源:packages/toxic-flow-auditor/README.md,提交 1a93a7c
工具
0版本歷史
1- v0.1.14最新Oct 9, 2026


