Tool · curated 5 Oct 2026
GitHub - TsvetanG2/mcpward: Black-box security & contract testing for MCP servers. Catch rug-pulls, tool poisoning, schema drift & protocol violations in CI — with JUnit & SARIF reports.
First reported github.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
mcpward gives defenders a way to catch MCP server tool-poisoning and rug-pull attacks against AI agents directly in their CI pipelines, hardening the agentic tool supply chain.
mcpward is an open-source black-box security and contract testing tool for Model Context Protocol (MCP) servers that detects rug-pulls, tool poisoning, schema drift, and protocol violations in CI, producing JUnit and SARIF reports. The GitHub repository is actively maintained with releases and CI integration.