AgentWall attack-surface scanner

Map the declared tools your agent can reach.

Paste a JSON-shaped MCP configuration or tool manifest for a transparent static-analysis review of declared configuration signals. AgentWall does not call tools, contact MCP servers, or perform a live infrastructure scan.

Local-only assessment

Your pasted configuration stays in this open browser tab and is not saved or sent to AgentWall. Do not paste credentials, tokens, or other secrets.

Step 1 · configuration

Paste a manifest

This scanner inspects JSON fields and declared tool metadata only; it never executes a tool or follows an endpoint.

Paste a configuration to begin. Nothing is retained.

Step 2 · static-analysis report

Configuration-risk signals will appear here.

This local heuristic summarizes declared configuration signals and gaps. It is not an assurance rating, certification, live scan, or runtime authorization decision.

No input is persisted or transmitted. Invalid JSON clears any previous report so it cannot be mistaken for the current manifest.

This public MVP evaluates only static JSON signals in your browser. It does not retain, transmit, or persist input; it does not validate runtime controls, discover remote tools, test infrastructure, or provide a security certification or guarantee.

    AgentWall by Alpha&Beta Solutions | The Firewall Between AI and Action