Skip to main content

Before installing a new MCP server

Run a targeted scan before adding anything to your config.
If the score is below 70 or the --explain output surfaces credential access or shell execution findings, pause and review before proceeding.

Morning check

Review what your agents did overnight in under 30 seconds.
For coding agent sessions with high tool-call volume, suppress routine noise:

Something looks wrong - investigate

Use this flow when a kill chain hit surfaces or an agent behaved unexpectedly.
If you suspect a server is actively serving different tools than it advertised:
To actively probe a server you own and control:

Weekly hygiene

Run these once a week to catch drift and credential sprawl.
Hooks are commands the agent runs automatically on tool-use, stop, or prompt-submit. They are standing executable state most people forget, and the target a persistence path would write, so they are worth a periodic look even when nothing is wrong. Schedule the full scan as a cron job so you get a weekly baseline automatically: