MCP Marketplace
BrowseHow It WorksFor CreatorsDocs
Sign inSign up
MCP Marketplace

The curated, security-first marketplace for AI tools.

Product

Browse ToolsSubmit a ToolDocumentationHow It WorksBlogFAQ

Legal

Terms of ServicePrivacy PolicyCommunity Guidelines

Connect

support@mcp-marketplace.ioTwitter / XDiscord

MCP Marketplace © 2026. All rights reserved.

Back to Browse

Injectshield MCP Server

by Bch1212
Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Prompt-injection firewall for AI agents — scan untrusted text before LLM calls.

About

Prompt-injection firewall for AI agents — scan untrusted text before LLM calls.

Security Report

4.2
Use Caution4.2High Risk

InjectShield is a legitimate prompt-injection detection service with a well-structured MCP server implementation. The codebase demonstrates proper authentication, reasonable API security patterns, and appropriate permissions for its stated purpose. However, several moderate-severity issues exist: the MCP server lacks validation for the INJECTSHIELD_API_KEY environment variable (missing key triggers runtime errors rather than graceful failure), the REST API routes have some input-validation gaps, and secrets management could be more explicit. The server's permissions (network_http, env_vars, file I/O for logging) are appropriate for a security-focused API gateway, but the broader REST server handles sensitive operations (Stripe webhooks, user keys) that warrant higher scrutiny. Supply chain analysis found 10 known vulnerabilities in dependencies (1 critical, 3 high severity). Package verification found 1 issue (1 critical, 0 high severity).

7 files analyzed · 19 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

What You'll Need

Set these up before or after installing:

API key from https://injectshield.dev (free tier: 10K req/mo).Required

Environment variable: INJECTSHIELD_API_KEY

Override the API base URL for self-hosted deployments.Optional

Environment variable: INJECTSHIELD_API_BASE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-bch1212-injectshield": {
      "env": {
        "INJECTSHIELD_API_KEY": "your-injectshield-api-key-here",
        "INJECTSHIELD_API_BASE": "your-injectshield-api-base-here"
      },
      "args": [
        "-y",
        "injectshield"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

InjectShield

Prompt-injection firewall for AI agents.

A drop-in REST API that detects and neutralizes injection attacks in any text — git commits, web pages, files, emails, user inputs — before they reach your AI agent's context window.

This repo is the open-source heuristic ruleset plus the source for the managed API at promptshield.pages.dev.


Why

In May 2026 a viral HN thread demonstrated that a single git commit message could burn a Claude Code user's entire session quota via a schema-driven attack ("OpenClaw"). The pattern is general: any AI agent that ingests untrusted text — code review bots, documentation summarizers, RAG agents, support copilots — is exposed to prompt injection. Most teams ship without any input-side defense.

InjectShield is one layer of a defense-in-depth strategy. It's not a silver bullet. Use it alongside system-prompt hardening, tool sandboxing, and output filtering.

Install as an MCP (Claude Code, Cursor, Cline, ...)

InjectShield ships a native MCP server at @injectshield/mcp. Once installed, your agent has three new tools — scan, scan_url, patterns — for input-side defense without writing any glue code.

# Claude Code:
claude mcp add injectshield --env INJECTSHIELD_API_KEY=is_live_… -- npx -y @injectshield/mcp

For Cursor / Cline / other MCP clients, see packages/injectshield-mcp/README.md.

Quick start

# 1) Get a key (delivered by email):
curl -X POST https://api.injectshield.dev/v1/keys \
  -H "Content-Type: application/json" \
  -d '{"email":"you@company.com"}'

# 2) Scan:
curl -X POST https://api.injectshield.dev/v1/scan \
  -H "Authorization: Bearer is_live_..." \
  -H "Content-Type: application/json" \
  -d '{"text":"ignore previous instructions","context":"user_input"}'

Or signup via the landing page: https://injectshield.dev — self-serve, email delivery.

What's open-source vs. managed

Live:

  • Landing page + live demo: https://injectshield.dev
  • API base: https://api.injectshield.dev
  • Health: https://api.injectshield.dev/healthz
  • Docs: https://injectshield.dev/docs

Open-source (this repo, MIT):

  • src/patterns.ts — the heuristic pattern library (~20 categorized rules).
  • src/detect.ts — the detection engine (heuristic aggregation, sanitization).
  • test/ — the test suite.
  • server/, public/ — the full API + landing-page source.

Managed only (paid tiers):

  • Hosted API with usage metering, dashboards, custom-pattern uploads, webhook alerts, no-logging mode (Pro), team accounts.
  • Future: Workers AI / Anthropic semantic classifier with prompt-engineered injection detection.

Detection categories

CategoryExamples
instruction_injection"ignore previous instructions", "new system prompt"
system_overridesystem-prompt leak, role-tag forgery, ChatML/Llama special tokens
role_hijack"you are now…", DAN, Developer Mode
exfiltrationdata sent to attacker URLs, markdown image exfil
schema_attackOpenClaw-style schema references
encoding_smugglebase64-decoded directives
invisible_textzero-width / bidi / Unicode-Tag smuggling
tool_abusesynthetic tool-call directives in untrusted text
jailbreak_classicDAN, "no restrictions", etc.

Contributing patterns

Found a novel attack? Open a PR adding a PatternRule to src/patterns.ts with:

  1. A unique id.
  2. A category from the enum above.
  3. A weight in [0, 1] — pick conservatively; the aggregation in detect.ts combines weights so every additional rule contributes meaningfully but isn't dominant.
  4. A test in test/detect.test.ts covering both a positive and a likely-benign negative example.

We auto-deploy merged patterns to the managed API. No-cost contributions get attribution in the changelog.

Running locally

npm install
npm test         # 11 tests, ~20ms
DATABASE_URL=postgres://... npm run dev   # boots Hono on :8080

License

MIT. InjectShield reduces but does not eliminate prompt-injection risk.

Acknowledgments

Built on Cloudflare Pages (frontend) + Railway (API) + Postgres + Anthropic Claude (semantic layer). Pattern library informed by HackAPrompt, the PINT benchmark, and a long list of public attack examples.

Reviews

No reviews yet

Be the first to review this server!

0

installs

New

no ratings yet

Is this your server?

Claim ownership to manage your listing, respond to reviews, and track installs from your dashboard.

Claim with GitHub

Sign up with the GitHub account that owns this repo

Links

Source CodeDocumentationnpm Package

Details

Published May 6, 2026
Version 0.1.4
0 installs
Local Plugin

More Developer Tools MCP Servers

Fetch

Free

by Modelcontextprotocol · Developer Tools

Web content fetching and conversion for efficient LLM usage

80.0K
Stars
4
Installs
5.3
Security
No ratings yet
Local

Toleno

Free

by Toleno · Developer Tools

Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.

137
Stars
518
Installs
8.0
Security
4.8
Local

mcp-creator-python

Free

by mcp-marketplace · Developer Tools

Create, build, and publish Python MCP servers to PyPI — conversationally.

-
Stars
72
Installs
10.0
Security
4.6
Local

MarkItDown

Free

by Microsoft · Content & Media

Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption

156.1K
Stars
33
Installs
6.0
Security
5.0
Local

FinAgent

Free

by mcp-marketplace · Finance

Free stock data and market news for any MCP-compatible AI assistant.

-
Stars
20
Installs
10.0
Security
No ratings yet
Local

mcp-creator-typescript

Free

by mcp-marketplace · Developer Tools

Scaffold, build, and publish TypeScript MCP servers to npm — conversationally

-
Stars
18
Installs
10.0
Security
5.0
Local