1. Conduid
  2. AI
  3. Checkpoint
MCP server · AI

Checkpoint

MCP Checkpoint continuously secures and monitors Model Context Protocol operations through static and dynamic scans, revealing hidden risks in agent-to-tool communications.

Unclaimed Apache-2.0 last commit 6 months ago model-context-protocolai-agentsmcpaisecurityairaagentic-ai
80Excellent

Scored yesterday · breakdown

About Checkpoint

Checkpoint is an MCP server published by aira-security in the AI category: mCP Checkpoint continuously secures and monitors Model Context Protocol operations through static and dynamic scans, revealing hidden risks in agent-to-tool communications. It has been installed 0 times through Conduid.

The repository has 111 stars and 9 forks, with the last commit 6 months ago. Six months or more without a commit doesn't mean the server is broken, but check the open issues (0) before depending on it in production.

Install

Install
npx mcp-checkpoint

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about Checkpoint

Powered by Claude · Grounded in docs

I know everything about Checkpoint. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • !Scoped permissionsDoesn't declare a permission scope. Assume it can do anything its process can.

Releases

v1.0.2mcp-armor-v1.0.2 · 27 Mar 2026Minor updates

README

🚀 Overview

MCP Armor is a comprehensive security scanner for Model Context Protocol (MCP). Automatically discovers, analyzes, and secures MCP servers integrated with all major Agentic IDEs, Agents and Clients.

MCP Armor

💡 Features

  • 🔍 Auto-Discovery: Finds known MCP configurations for popular Agentic IDEs like Cursor, Windsurf, VS Code, Claude Desktop, and more
  • 🔧 Tool, Resource & Prompt Inventory: Connects to MCP servers and catalogs available tools, resources, and prompt templates
  • 🛡️ Security Analysis: Specialized security checks including Prompt Injection, Rug Pull Attack, Cross-server Tool Shadowing, Tool Poisoning, Tool Name Ambiguity, and more..
  • 🧭 Baseline Drift Detection: Captures approved MCP components and detects rug pulls attacks
  • 📊 Comprehensive Reporting: Generates JSON and Markdown reports with actionable findings
  • 📜 Audit Trail: Timestamped baselines and reports for full traceability of changes and findings

🧰 Installation

pip install mcp-armor

🏃 Quick Start

# Scan all configurations with security analysis (auto-detects baseline.json if present)
mcp-armor scan

# Inspect configurations and generate baseline (defaults to baseline.json)
mcp-armor inspect

# Use custom configuration file
mcp-armor scan --config /path/to/config.json

# Scan multiple configuration files
 mcp-armor scan \
   --config /path/to/cursor.mcp.json \
   --config /path/to/vscode.mcp.json

# Use custom baseline file path
mcp-armor inspect --baseline /path/to/my-baseline.json
mcp-armor scan --baseline /path/to/my-baseline.json

# Generate markdown report
mcp-armor scan --report-type md

# Save to custom file
mcp-armor scan --output my-report.json
mcp-armor scan --report-type md --output my-report.md

⚙️ Command Options

Option Description
--config Custom configuration file path (can be used multiple times)
--baseline Baseline file for drift detection (scan) or creation (inspect)
--report-type {json,md} Output format (default: json)
--output Custom output file path
--verbose Detailed terminal output
--show-logs Display debug logs in terminal

🔰 Security Checks

🛡️ Standard Checks

  • Prompt Injection
  • Indirect Prompt Injection
  • Cross-Server Tool Shadowing
  • Tool Poisoning
    • Prompt Injection in Tool Description, Name and Args
    • Command Injection in Tool Description, Name and Args
  • Tool Name Ambiguity
  • Command Injection
  • Excessive Tool Permissions
  • Hardcoded Secrets

🧭 Baseline Checks

Detects deviations from approved MCP components (requires a baseline generated via inspect mode):

  • Rug Pull Attack
    • Tool Modified
    • Resource Modified
    • Resource Template Modified
    • Prompt Modified

📃 Logging

Logs are automatically saved to logs/mcp_armor.log:

# Default: logs saved to file only
mcp-armor scan

# Show logs in terminal too
mcp-armor scan --show-logs

🧪 Demo

Test MCP Armor using our intentionally vulnerable MCP servers. For details, see the demo guide.

⚡ Want More?

This open-source version covers static MCP configuration scanning. For teams that need deeper protection, Aira Security offers a full enterprise platform with:

Capability Open Source Aira Platform
MCP config scanning
Prompt & command injection detection
Tool poisoning & shadowing checks
Hardcoded secrets detection
Runtime enforcement & blocking
Agent behavior policy enforcement (toxic flow analysis)
Skills scanner (agentic workflow & capability analysis)
Custom security policies
Aira dashboard (centralized visibility & alerting)
Complete Agentic Security (beyond MCP — Agents, Workflows, and Skills)

🚀 See Aira in Action to experience the full platform.

🌟 Community

Join our Slack - a space for developers and security engineers building together to secure AI agents.

❓ FAQs

Q: Is my source code ever shared, or does everything run locally?

MCP Armor runs entirely locally. Inspect and scan modes analyze your MCP configurations, detect MCP servers integrated with your agents, and evaluate them directly on your machine. Prompt injection checks use our open-source model Aira-security/FT-Llama-Prompt-Guard-2, downloaded from Hugging Face to your local environment, ensuring your data and code is never shared externally.

⚖️ License

Distributed under the Apache 2.0 License. See LICENSE for more information.

README mirrored from the source repository yesterday. The original is authoritative.

Questions

About Checkpoint

How do I install Checkpoint?

Run npx mcp-checkpoint, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is Checkpoint safe to use with an AI agent?

Its trust score is 80 out of 100 (excellent). It passes 0 of 1 static security checks; the failures are listed above. It has no ConduID identity yet, so agent calls to it are not receipted.

Is Checkpoint still maintained?

Yes — the latest release is v1.0.2 (27 Mar 2026), and the last commit was 6 months ago. The repository has 111 stars and 0 open issues.