Perimeter is a one-command audit for your agent toolchain — MCP servers, hooks and skills. It tells you what they can do, what they cost, and what changed since last week; then gates CI.
$ perimeter audit Perimeter — agent toolchain audit ====================================== Scanned 3 servers · 1 context file Verdict: [33mHIGH[0m 0 critical · 1 high · 2 medium · 3 low · 0 info ── Servers (3) ── shell-helper [33mMEDIUM[0m 2 caps · 2,600 tok · .mcp.json paybot [33mHIGH[0m 2 caps · 5,000 tok · .mcp.json websearch [36mLOW[0m 1 caps · 2,100 tok · .mcp.json ── Findings (7) ── [[33mMEDIUM[0m] RISK-FSWRITE · Filesystem write access shell-helper (@modelcontextprotocol/server-filesystem) — The server can create or modify files. Ensure writes are confined to the project directory. Fix: Pin the working directory; deny paths outside an allowlist. [[33mMEDIUM[0m] SUP-CREDS-ENV · Secrets present in server config env shell-helper (@modelcontextprotocol/server-filesystem) — Credential-like env vars are configured: API_TOKEN. They may be visible in version control. Fix: Reference secrets from the runtime secret store; never commit them. [[36mLOW[0m] SUP-UNPINNED · Unpinned package version shell-helper (@modelcontextprotocol/server-filesystem) — The server is fetched at runtime (npx/uvx) without a pinned version or lockfile. Fix: Pin an exact version or vendor the package into the lockfile. [[33mHIGH[0m] RISK-PAYMENT · Payment / financial capability paybot (@stripe/mcp) — The server can initiate transactions or alter balances. Unauthorised or prompt-injected calls can move money. Fix: Require a human approval gate; scope keys to a read-only or sandboxed account. [[36mLOW[0m] SUP-UNPINNED · Unpinned package version paybot (@stripe/mcp) — The server is fetched at runtime (npx/uvx) without a pinned version or lockfile. Fix: Pin an exact version or vendor the package into the lockfile. [[36mLOW[0m] SUP-UNPINNED · Unpinned package version websearch (@modelcontextprotocol/server-brave-search) — The server is fetched at runtime (npx/uvx) without a pinned version or lockfile. Fix: Pin an exact version or vendor the package into the lockfile. [[33mHIGH[0m] INJECT-002 · Suspicious instructions in agent context file AGENTS.md — Embedded instruction phrasing detected in AGENTS.md. An agent reads this text every session, so it can redirect behaviour. Fix: Review the file and remove embedded instruction phrasing; consider pinning or signing it. ── Cost ── model claude-sonnet · ~9,700 tokens/load · $0.10/load
Three questions, one command.
Catches tool poisoning, shell execution, file/credential access, payments, cloud writes and typosquatted packages — mapped to OWASP Agentic risks.
Every server burns context before it works. Measure the token footprint and dollar cost of your MCP configuration per load.
Record a baseline and flag servers that are new or silently changed — the rug-pull pattern attackers use.
--enforce exits non-zero on a finding. Block a PR before a poisoned tool reaches your agents.
perimeter session reads real agent logs and reports which tools were actually called, with exact token spend.
Text, JSON, Markdown, SARIF and a shareable HTML dashboard. Drop SARIF into GitHub code scanning.
Node built-ins only. Works offline. Install globally, run anywhere, never leaves your machine.
Two steps from an invisible setup to an audited one.
Signature-hashes every server you currently use.
Scores risk, measures cost, flags drift.
Blocks the PR / deploy when the verdict crosses your threshold.
The scanner is free and open source. Pay for governance at scale.
Runs on macOS, Linux and Windows.
$ npm install --global perimetercli $ perimeter audit Verdict: LOW (or CRITICAL, if you're on the bad kind of stack)
Not by default. The CLI is fully offline and only reads your local files. Hosted Pro features are opt-in.
MCP servers (Claude Code, Cursor, Claude Desktop, `.mcp.json`), plus agent instruction files like `AGENTS.md` and skills.
No — it's a heuristic, offline scan. It's a strong, fast first pass for CI and audit, not a runtime sandbox. Be honest about that in your own reviews.
The core CLI is MIT. Perimeter Pro is a separate hosted product.