DARINORCold Lab

Tools / Agent Config Checker

AI Agent Config Checker

Paste an agent config — .mcp.json, .claude/settings.json, or a system prompt — and get a static triage for leaked secrets, over-broad permissions, and instruction-like content. Runs entirely in your browser; nothing is uploaded.

Paste a config file, a system prompt, or any agent-related text. This is a first-pass triage, not a scanner: it catches obvious, well-known patterns and deliberately avoids false positives. It cannot detect semantic prompt injection — no static check ever will.

Findings3 high · 0 medium
  • Auto-approval or permission bypassHigh

    "root.mcpServers.fetch.autoApprove" is set to true.

    Fix — Require human approval for high-risk tools; auto-approve only read-only, low-risk tools.

  • OpenAI API keyHigh

    Found a value matching OpenAI API key (length 61).

    Line 7

    Fix — Rotate the key immediately and move it to a secret manager or environment variable. Never commit it to a config file.

  • Anthropic API keyHigh

    Found a value matching Anthropic API key (length 61).

    Line 7

    Fix — Rotate the key immediately and reference it via an environment variable instead of a literal value.

// About this tool

AI Agent Config Checker

This is a first-pass triage tool for AI agent configuration files. It scans the text you paste for high-signal secret patterns (OpenAI, Anthropic, AWS, GitHub, Slack, Google API keys, private key blocks, database URIs with embedded passwords, bearer tokens), broad permission flags (autoApprove, alwaysAllow, dangerouslySkipPermissions, wildcard tool grants, readAll/writeAll), and instruction-like phrases that can act as injection vectors when they appear in content the agent reads.

It runs a JSON-aware structural pass when the input parses as JSON — so findings carry exact paths like root.mcpServers.fetch.autoApprove — and a text-level pass for JSONC, YAML, and markdown configs. Findings are deduplicated between passes and sorted by severity, with a concrete remediation for every finding.

This is deliberately conservative: it skips environment-variable references and whole-value placeholders, and it cannot detect semantic prompt injection — no static check ever will. Treat the result as a starting triage, not a clean bill of health or a red-team report.

// When to use it

  • Audit an MCP config before wiring it into your agent

    Paste your .mcp.json and check for auto-approve flags, wildcard tool grants, and secrets sitting in env blocks before the server gets access to your environment.

  • Review a settings file inherited from a teammate or template

    Quickly see which permission flags and secret patterns a config you didn't write actually contains before trusting it in production.

  • Pair with the Prompt Injection Tester

    An agent's attack surface is both its config and its system prompt — scan the config here, then audit the prompt it runs on.

// Questions

Is my config uploaded to a server?

No. The scan runs entirely in your browser via JavaScript. Nothing is uploaded, logged, or transmitted — which is why it's safe to paste configs that contain real-looking secrets.

What does this tool detect?

High-signal secret patterns (OpenAI, Anthropic, AWS, GitHub, Slack, Google API keys, private key blocks, database URIs with embedded passwords, bearer tokens), broad permission flags (autoApprove, alwaysAllow, dangerouslySkipPermissions, wildcard tool grants, readAll/writeAll), and instruction-like phrases that can act as injection vectors in content the agent reads.

What does this tool NOT detect?

Semantic prompt injection, novel attack patterns, and anything that requires understanding meaning rather than matching patterns. This is a conservative triage — a clean result is not a clean bill of health.

Is this tool free?

Yes. Free, runs locally in your browser, no account required.

What config formats does it accept?

Strict JSON gets a structural pass with exact paths; JSONC, YAML, and markdown fall back to text-level heuristics. Paste any of them — or a system prompt — and the same checks run.