Tool · curated 5 Oct 2026

GitHub - TsvetanG2/mcpward: Black-box security & contract testing for MCP servers. Catch rug-pulls, tool poisoning, schema drift & protocol violations in CI — with JUnit & SARIF reports.

Coverage timeline

5 Oct 2026github.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

mcpward gives defenders a way to catch MCP server tool-poisoning and rug-pull attacks against AI agents directly in their CI pipelines, hardening the agentic tool supply chain.

mcpward is an open-source black-box security and contract testing tool for Model Context Protocol (MCP) servers that detects rug-pulls, tool poisoning, schema drift, and protocol violations in CI, producing JUnit and SARIF reports. The GitHub repository is actively maintained with releases and CI integration.