Open source trust scanner

Know what your AI tools
are really doing

Instant security scores for Chrome extensions, VS Code plugins, npm packages, and MCP servers. Catch permission risks and data leaks before you install.

Try it now — no account needed

Paste a Chrome extension ID, VS Code extension, npm package name, or MCP server URL

What we analyze

Four scanner engines, one unified trust score

Chrome Extensions

Analyze permissions and data access

VS Code Plugins

Inspect marketplace extensions

npm Packages

Audit dependencies and scripts

MCP Servers

Evaluate Model Context Protocol tools

How it works

Three steps to a safer AI stack

1

Paste the identifier

Drop in a Chrome extension ID, VS Code plugin name, npm package, or MCP server config.

2

We analyze everything

Permissions, data flows, developer history, privacy policies, and known vulnerabilities — all scored automatically.

3

Get a trust score

A 0–10 score with full breakdown, risk flags, and safer alternatives — so you can decide with confidence.

Example reports

0 tools
Loading...

Built for teams that ship with AI

Whether you're an individual dev or a security team

Developers

Vet extensions and packages before installing. Get a quick risk assessment on anything you add to your stack.

Security Teams

Monitor your org's approved tool list. Get alerts when risk profiles change. Export compliance reports.

Organizations

Team dashboards, API integration for CI/CD, and GitHub Actions to block risky tools before they ship.

Start scanning for free

No credit card required. Scan up to 10 tools per day on the free plan. Upgrade anytime for unlimited scans and team features.