Use Case

Test MCP workflows before they become trusted automation.

MCP workflows can expose tools, context, and approval paths. ShakerScan evaluates trace and metadata evidence so CI can enforce release policy.

Sample gate decision

block

MCP context oversharing detected

The workflow exposed more context than the tool needed. Policy blocks deployment until the context boundary is narrowed.

MCP trace:run-2026-04-29-17
tool metadata:customer_lookup scope
policy:mcp-release
evidence hash:sha256:8b7c...e21f
1

Provide MCP trace, tool metadata, or runtime target evidence.

2

Run MCP-focused checks for context oversharing and tool trust boundaries.

3

Normalize the result into findings and policy output.

4

Verify the gate decision before deployment or workflow activation.

Why ShakerScan

The output is a release control, not just a report.

ShakerScan is built around release evidence: a tested target, a policy result, a verifier command, and an approval path when risk needs human review.

Signed evidence

Evidence hashes and AI Gate attestations bind the decision to the target, environment, policy, probe pack, and release scope when signing is configured.

CI-verifiable decision

GitHub Actions or the shakerscan CLI can verify that the decision matches the expected repo, commit, branch, environment, target, policy, and evidence hash.

Approval workflow

When an eligible workflow is approved, scoped approval tokens record the reason, audience, expiry, and decision path instead of bypassing the gate silently.

Checklist

MCP gate checklist

Inventory tools, scopes, resources, and trust boundaries.

Check context sharing and command egress behavior.

Reject untrusted tool metadata or shadow-server rebinding paths.

Bind the decision to the workflow version under review.

Limitations

What this page does not claim

ShakerScan does not replace human security review, threat modeling, or a scoped penetration test.

AI Gate decisions depend on the configured target, probe pack, policy, scan profile, and available evidence.

Production targets require authorization, safe scope, rate limits, and operational approval.

FAQ

Is ShakerScan an AI pentesting replacement?

No. ShakerScan is a verifiable security gate for release workflows. It complements deeper manual testing by producing repeatable runtime evidence and CI-verifiable allow, block, or needs_approval decisions.

Can ShakerScan scan any target?

No. Targets must be owned by the customer or explicitly authorized. Production scans should use safe profiles, rate limits, and defined scope.