Vibeleaderboard
Index / tool
Visit bouncer.run
Category
Cybersecurity
Type
TOOL
Date

About

Bouncer is a security scanner that inspects npm packages and MCP servers before installation, reading published source files without executing them to flag install scripts that fetch or run code, access to SSH keys or cloud credentials, and suspicious data destinations. For MCP servers, it also detects hidden prompt injection instructions and invisible characters embedded in tool descriptions, producing a readable risk verdict before a user or AI agent installs anything.

Why it made the leaderboard

Lets developers vet an npm install or MCP server for hidden prompt injection and credential-stealing code before an autonomous coding agent runs it, closing a supply-chain gap specific to agent-driven installs.

Tags

securitynpmmcpsupply-chainprompt-injectionvulnerability-scanning

Media

Bouncer

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.