Agent Security Checks You Didn't Know You Needed: MCP Server Risk & Prompt-Injection Breach Detection
Community Article
Published
July 15, 2026
If you're building with MCP servers or AI agents that operate autonomously, there's a security surface most tooling doesn't cover yet. Is the MCP server you're connecting to actually trustworthy, and were an agent's credentials compromised through a route that looks nothing like a normal phishing email?
We just published RelayShield Agentic Attack Surface as an MCP server on Spaces. It includes four tools:
- MCP Server Risk — Typosquat detection, criminal IOC corpus check, and domain-registration age for any MCP server URL
- Prompt-Injection Breach Check — Flags credential exposure whose source suggests prompt-injection rather than traditional phishing/malware
- Tech Stack CVE Check — CISA KEV / high-EPSS CVEs targeting your declared agent framework (LangChain, CrewAI, AutoGPT, n8n self-hosted, etc.)
- Bulk Identity Risk — Hierarchical org + agent-identity risk scoring, built for AI agent governance use cases
Add it to your MCP client from your Spaces MCP settings, or connect directly. Each call needs your own RelayShield API key. Self-serve signup at api.relayshield.net/developers, pay only for the calls you make.
Try it: huggingface.co/spaces/relayshieldadmin/relayshield-agentic-attack-surface