Skip to content
Scan one machine free. No account. Nothing leaves your machine.
KeepRails

Why KeepRails

KeepRails vs mcp-scan

mcp-scan inspects MCP servers for prompt-injection and tool-poisoning. KeepRails maintains a bounded endpoint-resident AI inventory and change history.

Short answer

mcp-scan answers whether one MCP server looks malicious. KeepRails answers which endpoint-resident AI was observed, from which source, on which endpoint, and what changed. Run both.

Where mcp-scan wins

Prompt-injection and tool-poisoning detection on MCP tool descriptionsDepth on a single protocol rather than breadth across the endpointA focused threat verdict for one server

Where KeepRails wins

Covering agent CLIs, IDE AI, local models and SDK dependencies, not only MCPProducing a dated register mapped to control referencesEmitting evidence JSON and a CycloneDX AI-BOM an assessor can ingestDeclaring its own coverage boundary instead of implying completeness

Side by side

Dimensionmcp-scanKeepRails
What it inspects MCP servers and their tool descriptions Declared endpoint-resident AI collectors with explicit coverage boundaries
Primary output Findings for injection and tool-poisoning patterns A dated evidence register mapped to five compliance frameworks
Evidence artifact MCP-focused findings Evidence JSON, audit report, and CycloneDX AI-BOM
Fixes Reports; remediation is manual Evidence-backed, reversible changes you approve
Data handling Local scan Local scan; only sanitized tool-identity metadata leaves, on consent

mcp-scan is a focused MCP security scanner, and a good one: dedicated prompt-injection and tool-poisoning detection is exactly the kind of narrow, deep check worth running. KeepRails is aimed at a different question — not “is this one MCP server malicious?” but “which endpoint-resident AI assets were observed, from which source, and how do they map to audit controls?”

That means KeepRails scans multiple endpoint evidence sources and turns the result into a dated, source-attributed evidence register with per-tool findings. Where mcp-scan stops at MCP threat findings, KeepRails produces a source-attributed register across the endpoint AI surface. The two are complementary: run mcp-scan for deep MCP threat detection and KeepRails for endpoint inventory evidence.

Use both — that is the honest recommendation

The register becomes the input your assessor reviews, instead of the spreadsheet they distrust. Keep the human judgement; stop hand-collecting the inventory.

curl -fsSL https://staging.keeprails.dev/install.sh | sh