Scanners check MCP servers before you connect them. The attack happens after: an approved tool description quietly changes and your agent starts following instructions nobody read. RugSnare hash-pins every tool at approval, snares the drift, and fails your build.
Tools {name, description, inputSchema}, prompt templates, resource definitions — all hash-pinned at approval. Schema attacks (hidden session params) can't sneak in.
Maintainer update, compromised registry, silent path swap — rugsnare diff exits 1 and CI fails. The live proxy quarantines mid-session too. Shadow detection catches same-name tools across servers.
11 heuristics catch suspicious descriptions before you've pinned anything: "do not tell the user", "read ~/.ssh/id_rsa", "base64-encode and pass verbatim". No baseline needed.
| Mechanism | What it catches |
|---|---|
| Hash pinning (tools + prompts + resources) | ✔ any contract change after approval |
| Live proxy (observe → enforce) | ✔ mid-session swaps, quarantine in real-time |
| Cross-server shadow detection | ✔ same tool name on multiple servers |
| Advisory signals (11 heuristics) | ✔ suspicious descriptions on first contact |
| SARIF output | ✔ GitHub code scanning integration |
| Drift-feed (public canary) | ✔ daily monitoring of the MCP ecosystem |
Nine AI clients supported: Claude Code, Cursor, Windsurf, VS Code, Continue, Zed, Cline, ZCode, and any MCP-compatible client.
Honesty page, up front. RugSnare is maintained by an independent engineer. Payments (later, for the optional hosted panel) are crypto-only via self-hosted BTCPay — no processor can deplatform the project, and no bank decides whether your security tool exists.
What that means for trust: everything security-critical is open source (Apache-2.0); the core has zero npm dependencies; releases are signed and their hashes are pinned on-chain — rugsnare verify --onchain checks your install against a hash that has been in the ledger since release day. We pin our own releases exactly the way we pin tool descriptions. An independent security review is published before the enforcing proxy ships by default. If we ever go rogue — fork us. That's the license working as intended.
A 7-question research thread — written answers, 3 minutes, findings published openly. The early ones are grim: the most common answer to "who is responsible for the security of what your agent connects to?" is nobody.
The core is in active development, dogfooding its own attack corpus. Leave an email to get the launch note (Show HN day), or come poke the corpus — try to spot the poisoned v2 with your eyes before running the diff.