Skip to content
MoorAI
// mcp security

How to secure MCP servers for coding agents

To secure the MCP servers your coding agents use: approve each server before it runs, check every tool call’s arguments and every result, re-check a server when it changes, read its tool descriptions for hidden instructions, and vet the package it launches before you install it. MoorAI does each of these on the developer’s machine, for Claude Code through its hooks and for any stdio MCP host, such as Claude Desktop, through its MCP proxy. Arguments and results are checked on the device and never sent anywhere to be inspected.

Six MCP controls, and where MoorAI applies each

1. Approve servers before they run

MoorAI keeps an allow-list of approved MCP servers and enforces it at call time: a call to a server that is not on it is refused on an enforcing device. New servers move through a discovered → approved or denied lifecycle in the console. Claude Code has its own organization-level control too, a managed MCP allow-list; use both.

2. Check what goes into each tool call

The Claude Code hook inspects the arguments of every mcp__ tool call for secrets, personal and regulated data and policy violations before the call runs. On an enforcing device a finding can be blocked, held for a signed justification, or masked: the value is replaced with a content-free placeholder and the call goes ahead.

3. Treat what comes back as untrusted

An MCP response can carry instructions aimed at the model. MoorAI scans MCP results as inbound content for indirect prompt injection and secret spill: in Claude Code after the call (PostToolUse, which reports and warns the model because the tool has already run), and in the MCP proxy before the result reaches the agent, where a result can be refused.

4. Catch tool poisoning and invisible instructions

The proxy reads each server’s tool listing. It runs the injection detectors over tool descriptions and schemas, flags invisible payloads (Unicode tag characters, ANSI escapes, bidi overrides, variation selectors), and reports a description that tells the model to read a credential file — ~/.ssh/id_rsa, ~/.aws/credentials, .env, a browser or keychain store — and pass its contents into a call. That last check alone catches 10 of 38 tool-stage attacks in MoorAI’s test set and fires on 0 of 1,634 benign samples. A listing cannot be edited without misrepresenting the server, so a finding alerts, and if policy says block, the next call to that tool is refused.

5. Re-approve a server that changes (rug pulls)

A server that was safe when approved can change later. MoorAI knocks a server whose configuration changes after approval back to pending, so its tools do not run again until someone approves it again.

6. Vet the server before you install it

The first time MoorAI sees a server it scores it 0–100 (bands: good, fair, poor, bad) from its package name (typosquats of popular MCP servers, known-malicious packages, an unpinned npx -y), the copy already installed, and its tool listing. Opt in and it also checks the registry and whether the repository the package declares is really its own; mcpReputation.blockBelow refuses a low-scoring server. Before installing anything, scan it:

node ~/.moorai/cli/moorai-scan.mjs ./.mcp.json --packages     # download and statically analyse each server's package
node ~/.moorai/cli/moorai-scan.mjs --package npm:@scope/server   # one package (also pypi:, github:owner/repo)

The verdict comes from MoorAI’s own engine decisions: CLEAN, CAUTION, REVIEW or DO-NOT-INSTALL, with exit codes for CI. Nothing in the package is executed, and only its name and version (or, for a GitHub source, the owner, repository and ref) leave the device. SkillTriage runs the same engine in a browser tab, no account, and its catalogue carries scans of the MCP servers people install most.

Where each control runs

  • Claude Code: the hook sees every mcp__ call and result, alongside file reads, shell commands and writes. Enforcement is validated end to end on Claude Code.
  • Claude Desktop and other stdio MCP hosts: the MCP proxy wraps each server and enforces in both directions. Measured against 12 malicious actions, it refused all 12 while enforcing (8 by the argument scan, 2 by the result scan) and forwarded 4 of 4 benign ones. But only 4 of those 12 actions travel over MCP at all; the rest reach the machine through a host’s built-in tools, where the proxy sees nothing.
  • Codex CLI, Copilot CLI, Gemini CLI and Cursor: their pre-tool hooks carry MCP calls to the same engine; these adapters are tested against each vendor’s documented payloads, not yet against the live agents.

Without enrollment MoorAI coaches instead of blocking, and posts nothing. The console, free for up to 200 users, turns on enforcement. Related: tool poisoning, tool-name shadowing, MCP, MoorAI vs Backslash (an MCP proxy), OWASP Agentic Top 10, every boundary an AI coding agent crosses, mapped to MITRE ATLAS.

// faq

Poisoning, rug pulls, and hosts.

What is MCP tool poisoning?

Tool poisoning is an instruction hidden in an MCP server’s tool description or schema, which the model reads as guidance, for example telling it to read ~/.ssh/id_rsa and pass the contents in a parameter. MoorAI’s MCP proxy scans tool listings for injection, for invisible characters, and for descriptions that ask the model to read or send a credential file.

What is an MCP rug pull?

A rug pull is an MCP server that changes after you approved it. MoorAI knocks a server whose configuration changes after approval back to pending, so it has to be approved again before its tools run.

Does MoorAI work with Claude Desktop and other MCP hosts?

Yes, for MCP traffic. MoorAI’s stdio MCP proxy wraps a server and checks tool calls and results in any host that launches stdio MCP servers, such as Claude Desktop. It sees only MCP: actions a host takes through its own built-in tools need that host’s hook, which MoorAI has for Claude Code, Codex CLI, Copilot CLI, Gemini CLI and Cursor.

Does MoorAI send MCP arguments or responses anywhere?

No. Arguments and results are checked on the device. An enrolled device sends the console a category, a risk level and a keyed one-way hash. The optional registry lookup sends only a public package name and version.

Every MCP call,
checked on the device.

Open source (MIT). Coaches with no account; enforces once enrolled.