Why KeepRails
KeepRails vs mcp-scan
mcp-scan inspects MCP servers for prompt-injection and tool-poisoning. KeepRails maintains a bounded endpoint-resident AI inventory and change history.
Short answer
mcp-scan answers whether one MCP server looks malicious. KeepRails answers which endpoint-resident AI was observed, from which source, on which endpoint, and what changed. Run both.
Where mcp-scan wins
Where KeepRails wins
Side by side
mcp-scan is a focused MCP security scanner, and a good one: dedicated prompt-injection and tool-poisoning detection is exactly the kind of narrow, deep check worth running. KeepRails is aimed at a different question — not “is this one MCP server malicious?” but “which endpoint-resident AI assets were observed, from which source, and how do they map to audit controls?”
That means KeepRails scans multiple endpoint evidence sources and turns the result into a dated, source-attributed evidence register with per-tool findings. Where mcp-scan stops at MCP threat findings, KeepRails produces a source-attributed register across the endpoint AI surface. The two are complementary: run mcp-scan for deep MCP threat detection and KeepRails for endpoint inventory evidence.
Use both — that is the honest recommendation
The register becomes the input your assessor reviews, instead of the spreadsheet they distrust. Keep the human judgement; stop hand-collecting the inventory.
curl -fsSL https://staging.keeprails.dev/install.sh | sh