WebMCP Security Checker
Check browser-registered WebMCP tools locally for unsafe exposure, missing confirmation, weak schemas, and 7 more assurance controls.
Local analyzer · Files and pasted code never leave your device.
Get a useful answer before creating an account. Each focused check runs in your browser, keeps sensitive input on your device, and states what it cannot prove.
Check browser-registered WebMCP tools locally for unsafe exposure, missing confirmation, weak schemas, and 7 more assurance controls.
Local analyzer · Files and pasted code never leave your device.
Use a free AI app security checklist to document launch controls, find the most important gaps, and prioritize what to verify before release.
Local analyzer · No code or target data is collected.
Scan selected source files locally for AI-specific security signals mapped to the OWASP Top 10 for LLM Applications (2025).
Local analyzer · Files and pasted code never leave your device.
Paste HTTP response headers into this free local checker to review CSP, HSTS, CORS, clickjacking, referrer, permissions, and cookie signals.
Local analyzer · Headers stay in your browser.
Scan selected text files locally for common API keys, access tokens, private keys, and assigned credentials. Matches are redacted and never uploaded.
Local analyzer · Files never leave your device.
Review pasted Supabase RLS policy SQL locally for missing enablement, permissive rules, bypass risks, and absent ownership or tenant predicates.
Local analyzer · SQL stays in your browser.
Decode a non-production JWT locally, inspect algorithm and time claims, and review Secure, HttpOnly, and SameSite attributes on session cookies.
Local analyzer · Tokens are decoded locally and are never verified or sent.
Each tool performs a focused deterministic check in your browser. The page explains exactly what input it reviews, what signals it reports, and what the result cannot establish.
No. The checklist, pasted headers, selected files, SQL, JWTs, and cookie values are processed on your device by the page code. Use non-production tokens and review each tool's stated limits.
No. Each tool reports a focused set of signals. A clear result does not prove the whole application is secure; it only means the specific checks did not find a signal.
The complete product adds authorized target scanning, SCA and secret checks, explicit coverage receipts, evidence states, approval-gated fix proposals, server-owned retests, immutable reports, schedules, notifications, and workspace-scoped audit history. Read the evidence methodology before interpreting a result.