Toxic Flow Auditor

io.github.GuardBeev0.1.14更新於 Oct 9, 2026

Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress

概覽

AI 產生的概覽

稽核 MCP 工具目錄或伺服器原始碼中的致命三要素風險流:不受信任輸入、敏感資料與外送。

功能
這個本機 MCP 伺服器會對工具目錄或 MCP 伺服器原始碼做靜態分析,標出危險的能力組合。工具包括 audit_catalog(分析 tools/list 形式的 JSON 傾印)、scan_source、scan_file 與 scan_directory(擷取 .tool(...) 註冊),以及 explain_trifecta(說明此模型)。它會回報致命三要素、單一工具三要素,以及敏感+外送、不受信任+破壞等危險組合,並給出 A-F 評級。僅做靜態分析,不會呼叫實際工具。
適用情境
適合在審查或發佈 MCP 伺服器時使用,用來判斷某個伺服器是否同時具備取得不受信任內容、存取敏感資料,以及外送或刪除資料的能力。適用於安裝前或發佈前的工具目錄與原始碼樹審查,也包含土耳其 PII(KVKK)啟發式規則。
執行需求
以本機 stdio 程序執行,從 npm 套件 @guardbee/mcp-toxic-flow-auditor 安裝,需要 Node.js。不需要 API 金鑰,未宣告環境變數或標頭。也可透過 npx 使用命令列。除非關閉,否則會連線傳送遙測。
安裝前請注意
此套件預設傳送使用遙測(工具名稱與簡短參數,不包含被掃描的程式碼),可用 GUARDBEE_TELEMETRY=0 關閉。它只讀取目錄與原始碼文字,不呼叫實際工具,因此結論屬於啟發式判斷,可能對名稱產生誤判。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Toxic Flow Auditor,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

@guardbee/mcp-toxic-flow-auditor

🇬🇧 English | 🇹🇷 Türkçe | 🇨🇳 中文

An MCP server that audits an MCP tool catalog for toxic flows — Simon Willison's lethal trifecta:

  1. Untrusted content (fetch, scrape, browse, issues, feeds)
  2. Sensitive / private data (vault, DB, secrets, KVKK-regulated PII)
  3. Exfiltration or destruction (send, webhook, export, delete, drop)

When one MCP server exposes all three, a single prompt injection can chain them. Mapped primarily to OWASP MCP10:2025.

This package sends usage telemetry by default (tool name + short parameters, scanned code is never included — see @guardbee/mcp-telemetry). Disable with GUARDBEE_TELEMETRY=0.

Claude ──► toxic-flow-auditor ──► tools/list JSON or MCP server source              │              ├─ lethal_trifecta      (untrusted + sensitive + outbound)              ├─ single_tool_trifecta (one tool alone spans all three)              ├─ sensitive_plus_exfil              ├─ untrusted_plus_exfil              └─ sensitive_plus_destruct

What it flags

  • Lethal trifecta across the catalog. Tools that fetch untrusted content, reach vault/DB/PII, and can send data out or destroy it — on the same server.
  • Single-tool trifecta. One registration whose name/description itself spans all three capabilities.
  • Dangerous pairs. Sensitive+exfil, untrusted+exfil, or sensitive+destructive even when the full trifecta is not present.
  • KVKK-aware heuristics. Turkish PII signals (tc_kimlik, müşteri, KVKK) count as sensitive data.
  • snake_case names read word by word. read_vault_secret and drop_table are classified by each word; opening a pull request counts as exfiltration.

Grades A–F. No API key. Static / catalog analysis only — does not call live tools.

The classification rules come from @guardbee/guard-core; @guardbee/mcp-security-proxy uses the same rules to block toxic flows at runtime.

Tools

ToolPurpose
audit_catalogAudit a tools/list-shaped JSON dump
scan_sourceExtract .tool(...) registrations from source text
scan_fileScan one source file
scan_directoryRecursive scan; merges tools across files
explain_trifectaExplain the model

CLI

npx @guardbee/mcp-toxic-flow-auditor audit <tools.json> [--fail-on=any] [--format=text|json|sarif]npx @guardbee/mcp-toxic-flow-auditor scan <path>        [--fail-on=any] [--format=text|json|sarif]

Example catalog:

json
{  "tools": [    { "name": "fetch_page", "description": "Scrape a URL" },    { "name": "read_vault_secret", "description": "Read API key from vault" },    { "name": "send_slack_message", "description": "Post to webhook" }  ]}

來源:packages/toxic-flow-auditor/README.md,提交 1a93a7c

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.14最新Oct 9, 2026