Shieldapi Mcp

Created By
alberthild3 months ago
AI-native security tools via MCP. Prompt injection detection (208 patterns, 8 languages, <100ms), skill supply chain scanning (204 patterns, 8 risk categories), plus URL/domain/IP/email/password checks. Pay-per-request with USDC via x402 — no API keys needed. 9 tools, demo mode included.
Overview

Security intelligence for AI agents

ShieldAPI provides 9 security tools via MCP — from password breach checks to prompt injection detection. All tools work in free demo mode out of the box. Paid mode uses x402 USDC micropayments on Base.

Tools

ToolWhat it doesPrice
check_passwordSHA-1 hash against 900M+ breached passwords (HIBP)$0.001
check_password_rangek-Anonymity password range lookup$0.001
check_emailEmail breach exposure via HIBP$0.005
check_domainDNS, SPF/DMARC, SSL, blacklist reputation$0.003
check_ipBlacklists, Tor exit detection, reverse DNS$0.002
check_urlPhishing, malware, brand impersonation$0.003
full_scanAll checks combined in one call$0.010
check_promptPrompt injection detection — 200+ patterns, <100ms$0.005
scan_skillAI skill/plugin supply chain scanner — 8 risk categories$0.020

Quick Start

npx shieldapi-mcp

All tools work immediately in demo mode — no wallet, no API key needed.

Highlights

  • Prompt Injection Detection: 200+ patterns including Base64, ROT13, Unicode homoglyphs, DAN/jailbreak, exfiltration attempts
  • Skill Supply Chain Security: Scans for malicious code, credential leaks, suspicious downloads — based on Snyk ToxicSkills taxonomy
  • Real Breach Data: 900M+ password hashes from Have I Been Pwned
  • x402 Native: First security MCP server with pay-per-request USDC micropayments
  • No API Key: Works out of the box in demo mode, add a wallet for paid mode

Server Config

{
  "mcpServers": {
    "shieldapi": {
      "command": "npx",
      "args": [
        "-y",
        "shieldapi-mcp"
      ],
      "env": {
        "SHIELDAPI_WALLET_PRIVATE_KEY": "0x..."
      }
    }
  }
}
Project Info
Created At
3 months ago
Updated At
3 months ago
Author Name
alberthild
Star
-
Language
-
License
-
Category

Recommend Servers

View All
Bring your real authenticated browser session to AI coding agents. Local-first MCP server + Chrome MV3 extension. No cloud. No telemetry.
@Cubenest

peek records the user's actual logged-in browser (DOM via rrweb, console events, network metadata, optional response bodies via opt-in Deep capture) through a Chrome MV3 extension. The extension ships events through a native-messaging stdio bridge to a local MCP server (peek-mcp), which persists them to a SQLite database at ~/.peek/sessions.db. AI coding agents (Claude Code, Cursor, Cline, Windsurf) read sessions from the database via 10 MCP tools: Tool What it does list_recent_sessions List recently recorded sessions (id, origin, ts, event count). get_session_summary LLM-readable narrative summary of a session. get_session_console_errors Console errors recorded in a session. get_session_network_errors Failed/notable network requests in a session. get_user_action_before_error Last N user actions before a console error. generate_playwright_repro Generate a runnable Playwright test from a session. get_dom_snapshot Reconstruct the DOM at a given timestamp. query_dom_history Timeline of attribute/text changes for a selector. request_authorization Side-panel consent for write actions (Level 3). execute_action Dispatch a UI action (gated by permission level + destructive blocklist). Why local-first matters Every other "browser session for AI" tool ships to a vendor cloud. peek's SQLite + extension live on the user's machine — no remote endpoints, no telemetry. The privacy policy (docs/peek/PRIVACY_POLICY.md) is the source of truth. Install # 1. Add the MCP server to Claude Code claude mcp add peek -- npx -y @peekdev/mcp # 2. Install the Chrome extension from the Chrome Web Store # (link added once the CWS listing is approved)

a day ago