Bouncer
bouncer.run- Category
- Cybersecurity
- Type
- TOOL
- Date
About
Bouncer is a security scanner that inspects npm packages and MCP servers before installation, reading published source files without executing them to flag install scripts that fetch or run code, access to SSH keys or cloud credentials, and suspicious data destinations. For MCP servers, it also detects hidden prompt injection instructions and invisible characters embedded in tool descriptions, producing a readable risk verdict before a user or AI agent installs anything.
Why it made the leaderboard
Lets developers vet an npm install or MCP server for hidden prompt injection and credential-stealing code before an autonomous coding agent runs it, closing a supply-chain gap specific to agent-driven installs.
Tags
Media

Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.