Agent Utility MCP
About
Deterministic security preflight for AI agents. Check URLs, files and shell commands before acting.
Details
- Author
- Unknown
- Categories
- Developer Tools, Security, AI
Jump to
Analyze URLs for structural and security risk signals before access.
Inspect file metadata and content signatures without executing the file.
Analyze shell commands for destructive, privileged, network or remote-execution behavior without executing them.
Analyze proposed agent tool calls before execution and detect destructive actions, privilege changes, sensitive-data exposure, external transmission, financial operations, and other high-risk behavior.
Damage is predicted by where an action lands, not what it's called.rm -rf ./distscores 10.rm -rf /etcscores 90.
Callers pick permissive, balanced or strict. Critical rules ignore policy entirely — a compromised agent cannot disable the layer.
Never executes anything. No external API calls. No payloads, paths or arguments in telemetry.
Designed as a deterministic, read-only security preflight layer for AI agents. It executes no commands or files and makes no external API calls.
Deterministic analysisRead-onlyNo executionNo external APIs
MCP endpoint
https://agent-utility-mcp.insivotron.workers.dev/mcp
Status
Early preview · ruleset 1.0.0 · schema 0.3.0
Pricing
Free during product-market-fit validation
This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.
Remote MCP server (Streamable HTTP) at https://mcp.agenticrail.nz/ — deterministic step-order enforcement for AI agents. evaluate_step returns ALLOW or DENY before a step runs; verify_receipt proves a sequence's Ed25519-signed, hash-chained receipt chain is intact. No auth required: omit the bearer token and calls run on the public demo key. That first clause matters — the form has no "remote/hosted" field, and putting the endpoint in the description is the convention on that list ("Fully REMOTE! Just use…"). The rest mirrors your own server card verbatim, so the listing and the card can't drift.
EU AI Act compliance scanner for Python AI agents — 10 tools for scanning, analysis, and remediation
Arcjet is the runtime security platform that ships with your AI code.
Remediate vulnerabilities found by Contrast products using LLM and Coding Agent capabilities.
AES-256-GCM + Argon2id encrypted local vault that resolves {{PLACEHOLDER}} secrets for AI agent credentials.
MCP security scanner — finds tool poisoning, credential leaks, and insecure transports in AI agent configurations.
AMS – Deterministic Agent Pipeline with A2A‑style Orchestration and Cryptographic Audit
An AI penetration testing tool that uses natural language to operate various security tools like nmap, sqlmap, and metasploit.
Encrypted secrets vault for AI agents stores API keys in AES-256-GCM and resolves them at MCP runtime so plaintext never touches the LLM transcript.
Security scanner for MCP servers — detects tool poisoning, prompt injection, and 90+ vulnerability patterns
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.




