Tensorfire

Tensorfire

MCP server for security-testing AI models, exposing garak vulnerability scanning and URL/MCP-endpoint scanning as callable tools. It lets agents probe LLM endpoints for jailbreaks, prompt injection, and data leakage, and classify URLs or screen remote MCP endpoints for prompt-injection payloads.

Category
Visit Server

README

<picture> <source media="(prefers-color-scheme: dark)" srcset="images/lockup-on-dark-padded.png"> <img alt="Tensorfire" src="images/lockup-ink-red-1024.png" width="480"> </picture>

An MCP server, shipped as a container image, for security-testing AI models. It exposes two things behind one consistent tool interface:

  • garak vulnerability scanning — probe any OpenAI-compatible LLM endpoint for jailbreaks, prompt injection, toxicity, and data leakage.
  • URL / MCP-endpoint scanning — classify URLs for phishing/exfil traits and screen a remote MCP server's advertised tools for prompt-injection payloads.

Point any MCP client (an agent, an IDE, CI) at the server and it gets these as callable tools.

What Tensorfire is, and why we built it

AI security tooling is scattered across libraries that each bring their own CLI, config, and integration work. Wiring even one of them into an agent or a CI pipeline is repetitive glue.

Tensorfire puts that capability behind a single Model Context Protocol surface, so running a security test is a tool call rather than an integration project. This initial release keeps the scope deliberately small — an LLM vulnerability scan and URL/MCP screening — with room to add more tools over time.

Design principles:

  • Graceful degradation. The server always starts and always advertises its catalog. If an optional dependency is missing, the tool returns a structured "dependency unavailable" result instead of crashing.
  • Extensible. Tools are auto-discovered — dropping a module into src/tensorfire/tools/ adds a pack with no central wiring.
  • Secrets stay out of tool calls. Tools that hit a live model take the name of an environment variable holding the API key, never the key itself.

Tools

Pack Backed by Tools
garak garak garak_list_probes, garak_scan
mcp_url_scan built-in (MCP SDK) classify_url, scan_mcp_endpoint
prompt_injection built-in (offline) scan_text_for_injection

Plus tensorfire_catalog, which lists every pack and whether it's installed. Clients should call it first.

Deploy with Docker

# Build and run. Serves streamable HTTP on http://localhost:8000/mcp.
docker compose up --build

docker-compose.yml passes target-model secrets from your shell environment (OPENAI_API_KEY, OPENAI_BASE_URL) into the container and mounts ./workspace read-only for any files your tools need to reach.

Without compose:

docker build -t tensorfire:latest .
docker run -p 8000:8000 \
  -e OPENAI_API_KEY=your-key \
  -e OPENAI_BASE_URL=https://api.openai.com/v1 \
  tensorfire:latest

Deploy locally (no container)

python -m venv .venv && . .venv/bin/activate
pip install -e ".[dev]"          # installs the server + garak
tensorfire                          # serves http://localhost:8000/mcp

pip install pulls garak (and its ML dependencies), so the first install is large. Everything runs in this one environment — there is no separate build step.

Configuration

All optional, via environment variables:

Variable Default Purpose
TENSORFIRE_HOST 0.0.0.0 bind address
TENSORFIRE_PORT 8000 port
TENSORFIRE_TRANSPORT streamable-http set stdio for a stdio client
TENSORFIRE_LOG_LEVEL INFO log verbosity

Verify it's up

curl -fsS http://localhost:8000/health
# {"status":"ok","server":"tensorfire","packs_total":3,"packs_ready":3}

Use /health for liveness — never probe /mcp with a bare GET; it requires the MCP handshake and returns 406 Not Acceptable by design.

Connecting a client

Any MCP client that supports streamable HTTP:

{ "mcpServers": { "tensorfire": { "url": "http://localhost:8000/mcp" } } }

Clients should call tensorfire_catalog first, then call tools by name.

Running a garak scan

garak_scan defaults to a local Ollama server — no API key required.

  • model — the Ollama model name (e.g. llama3.1, gemma4:26b-a4b-it-q8_0).
  • base_url — only if Ollama isn't on 127.0.0.1:11434 (e.g. http://ollama:11434 when the server runs in another container). It's normalized to the host:port garak's Ollama client expects.
  • probes — comma-separated probe families (e.g. "promptinject,dan"); omit for garak's default set. Use garak_list_probes to see what's available.

Minimal call:

{ "model": "gemma4:26b-a4b-it-q8_0", "probes": "promptinject", "generations": 1 }

Testing an OpenAI-compatible endpoint instead

Set model_type to openai or openai.OpenAICompatible, base_url to the endpoint, and api_key_env to the name of the env var (in the server's environment) holding the key:

{
  "model": "gpt-4o-mini",
  "model_type": "openai",
  "api_key_env": "OPENAI_API_KEY",
  "probes": "promptinject"
}

API keys are never tool arguments. The agent passes api_key_env — the name of an environment variable inside the Tensorfire container that holds the key. Provision the actual secret via docker-compose.yml or -e.

Development

pip install -e ".[dev]"
pytest

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured