redcapraLaunch free workbench →

Free tool · Nothing you paste leaves your browser

Is your AI agent's config an attack surface?

Coding agents run with your permissions. Paste your settings.json, .mcp.json or hooks config and get a graded read on the classics: blanket shell allows, arbitrary-exec rules, unpinned auto-installing MCP servers, inline credentials, and hook commands that interpolate attacker-influenceable input. Analysis runs entirely in this page — no upload, no account.

Your web app deserves the same treatment.

RedCapra runs a real 47-check security scan on your site — headers, TLS and the fundamentals behind most real breaches — with findings tracked and reports generated, and your data staying in your browser. No credit card required · Free forever on Solo.

Run a free scan →

How this works: the analyzer is a few hundred lines of plain JavaScript running in this page. Nothing is uploaded, logged or stored — credential-shaped values are masked before they even appear in the findings text. It recognises the config shapes of Claude Code and MCP-style tool servers; other agents' configs may partially match.

Agent Config Scanner — free, in-browser | RedCapra