AgentAvow runs every MCP server it grades in a behavioral sandbox
AgentAvow now executes MCP servers in a fresh gVisor container: install, handshake, and one call per tool with deterministically generated arguments and planted canary credentials. Of 20 popular servers, 16 completed a full run, yielding 4 undeclared-egress findings and zero false positives.
- 16 of 20 popular MCP servers completed a full sandbox run
- 4 findings: egress to hosts outside vendor and declarations
- No planted credentials leaked in any run
- Critical finding caps the trust score at 45
Read next
Security