Inkog MCP server
Security co-pilot for AI agents. Scan for vulnerabilities, audit MCP servers, verify governance.
3 stars98 downloads/wk
Reviews
Write oneNobody has reviewed Inkog yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Inkog tools (7)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
inkog_audit_a2aAudit Agent-to-Agent (A2A) communications in multi-agent systems. Detects infinite delegation loops, privilege escalation, data leakage between agents, and unauthorized handoffs. Supports Google A2A protocol, CrewAI, LangGraph, and AutoGen. Use this when building or reviewing multi-agent systems to detect delegation vulnerabilities.
inkog_audit_mcp_serverSecurity audit any MCP server from the registry or GitHub. Analyzes tool permissions, data flow risks, input validation, and potential vulnerabilities. Use this before installing any new MCP server to verify it is safe.
inkog_compliance_reportGenerate a compliance report for EU AI Act, NIST AI RMF, ISO 42001, or OWASP LLM Top 10. Analyzes agent code and maps findings to regulatory requirements. Use this when preparing AI agents for regulatory compliance or audit.
inkog_explain_findingGet detailed explanation and remediation guidance for a security finding or pattern. Includes what the issue is, why it's dangerous, step-by-step fixes, and code examples. Use this after scanning to understand how to fix security findings.
inkog_generate_mlbomGenerate a Machine Learning Bill of Materials (MLBOM) for AI agents. Lists all models, tools, data sources, frameworks, and dependencies. Supports CycloneDX and SPDX formats. Use this when documenting AI agent dependencies for supply chain compliance.
inkog_scanSecurity co-pilot for AI agent development. Scans for prompt injection, infinite loops, token bombing, SQL injection via LLM, and missing guardrails. Supports LangChain, CrewAI, LangGraph, AutoGen, n8n, and 20+ agent frameworks. Use this whenever building, reviewing, or deploying AI agents to catch security issues before they reach production.
inkog_verify_governanceValidate that AGENTS.md declarations match actual code behavior. Detects governance mismatches like 'read-only declared but code writes data' or 'human approval required but no approval gates in code'. Essential for EU AI Act Article 14 compliance. Use this whenever an AI agent project has an AGENTS.md file, or to verify governance compliance before deployment.
Public scan report
scanner v0.1.10 · 2026-09-28 · same rubric, same numbers if you re-run it
- Code scan33 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 12 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (1)
- mediumeval / new Function used
exec.evaldist/utils/agent-detector.js: …ENSITIVE_PATTERNS = [ 'exec(', 'eval(', 'subprocess', 'os.system', …
Install Inkog in Claude Code, Cursor or VS Code
Runs npx -y @inkog-io/mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add inkog -- npx -y @inkog-io/mcp
What the publisher says
From the Inkog repository's README, as published. We do not edit it. Read it on GitHub
Inkog MCP Server
Security companion for AI agent development in Claude, Cursor, and Claude Code.
Ask your AI pair-programmer to build an agent. Inkog checks it as you code — scanning for vulnerabilities, explaining findings in plain English, verifying AGENTS.md governance, and auditing agent-to-agent delegation. All inside the same conversation, no context switch.
Available in Claude Desktop, Cursor, Claude Code, ChatGPT, and any MCP-compatible client.
The Dev-Flow Loop
Inkog is designed to live inside the conversation where you build the agent — not as a post-hoc gate:
- Ask Claude to build a piece of agent logic.
- Ask Claude to scan it with Inkog — "Scan this with Inkog and show me any CRITICAL or HIGH findings."
- Ask Claude to explain each finding in plain English — "Explain the top finding. What's the risk, and how do I fix it?"
- Ask Claude to apply the fixes. Review the diff, approve, re-scan.
- Before shipping, verify governance — "Verify my AGENTS.md against the code" and "Audit the agent-to-agent delegation".
Read the full walkthrough: Building Secure AI Agents with Claude Code and the Inkog MCP.
Recommended prompts
- "Scan the current directory with Inkog and show me any CRITICAL or HIGH findings."
- "Explain the top finding in plain English. What's the risk, and how do I fix it?"
- "Verify my AGENTS.md against the code."
- "Audit the agent-to-agent delegation in this crew."
- "Run a compliance report and map the findings to EU AI Act Articles 12, 14, and 15."
- "Audit the MCP servers I'm integrating with."
When to Use Inkog
- Building an AI agent — Scan during development to catch infinite loops, prompt injection, and missing guardrails before they ship
- Adding security to CI/CD — Add inkog-io/inkog@v1 to GitHub Actions for automated security gates on every PR
- Preparing for EU AI Act — Generate compliance reports mapping your agent to Article 14, NIST AI RMF, OWASP LLM Top 10
- Reviewing agent code — Use from Claude Code, Cursor, or any MCP client to get security analysis while you code
- Auditing MCP servers — Check any MCP server for tool poisoning, privilege escalation, or data exfiltration before installing
- Verifying AGENTS.md — Validate that governance declarations match actual code behavior
- Building multi-agent systems — Detect delegation loops, privilege escalation, and unauthorized handoffs between agents
What Inkog Does
- Logic Flaw Detection: Find infinite loops, recursion risks, and missing exit conditions
- Security Analysis: Detect prompt injection paths, unconstrained tools, and data leakage risks
- AGENTS.md Governance: Validate that code behavior matches governance declarations
- Compliance Reporting: Generate reports for EU AI Act, NIST AI RMF, OWASP LLM Top 10
- MCP Server Auditing: Audit any MCP server before installation
- Multi-Agent Analysis: Audit Agent-to-Agent communications for logic and security issues
Installation
Claude Desktop
Add to your claudedesktopconfig.json:
{
"mcpServers": {
"inkog": {
"command": "npx",
"args": ["-y", "@inkog-io/mcp"],
"env": {
"INKOG_API_KEY": "sk_live_your_api_key"
}
}
}
}Cursor
Add to your Cursor MCP settings:
{
"mcpServers": {
"inkog": {
"command": "npx",
"args": ["-y", "@inkog-io/mcp"],
"env": {
"INKOG_API_KEY": "sk_live_your_api_key"
}
}
}
}Global Installation
npm install -g @inkog-io/mcpShortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Inkog: common questions
- Is Inkog MCP server safe?
- Mostly: it is graded B (74/100). Read the Inkog safety report
- How do I install Inkog?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Inkog need an API key?
- Yes. The registry entry asks for
INKOG_API_KEY. - Is Inkog maintained?
- The last commit was 12 days ago (2026-09-16). The latest release is v1.0.20.
- What can I use instead of Inkog?
- Servers from other publishers that do the same job: Mastyf AI MCP server, Wireshark MCP server and Solana Security Standard MCP server. Compare all Inkog alternatives.
Alternatives to Inkog
Same job from other publishers: the closest match first, then the best rated.
- Mastyf AIRuntime proxy for MCP security, cost governance & auditnot reviewedGrowingB
- WiresharkProfessional network analysis with tshark. Security audits, deep-dives, and threat detection.not reviewedEstablishedA
- Solana Security StandardScan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.not reviewedGrowingA
DNS DoctorScan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.not reviewedGrowingA- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB