Deepsleuth
PulseGate's liveness check found it on 7 Oct 2026; it is registered on GitHub and PyPI and has been in the index since 6 Oct 2026. How this is checked
Deepsleuth is an Apache-2.0 security scanner for Model Context Protocol servers. It performs deterministic analysis to provide deep visibility into MCP server risks, including supply-chain issues, prompt injection, and tool poisoning, without using an LLM.
Inferred · not functionally tested
Overview
6 featuresPurpose: Detecting security risks such as prompt injection and tool poisoning in MCP servers without relying on an LLM.
Inferred · not functionally tested
Audience: developers and security teams building or auditing MCP servers
Inferred · not functionally tested
Functions: data_extraction, monitoring
Inferred · not functionally tested
Interfaces: API: unknown · MCP: indicated (inferred, not tested) · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)
Recorded constraints: pricing: open_source · license: Apache-2.0 · platforms: CLI · deployment: cli, self_hosted
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org · github.com. These links do not verify the individual claims.
In the AI & LLM security space, Deepsleuth takes a focused approach. Inferred · not functionally tested: It focuses on detecting security risks such as prompt injection and tool poisoning in MCP servers without relying on an LLM. Inferred · not functionally tested: Deepsleuth is an open-source project aimed at developers and security teams building or auditing MCP servers. Basis unknown · not verified: Deepsleuth is open source under the Apache-2.0 license. Basis unknown · not verified: Deepsleuth is available on the command line, and it can be self-hosted.
DeepSleuth builds and maintains Deepsleuth, and it first shipped in 2025. Development happens publicly on GitHub with 138 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include MCP server scanning, deterministic analysis, and supply-chain checks. Basis unknown · not verified: Catalogued interfaces include an MCP server.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- MCP server scanning
- Deterministic analysis
- Supply-chain checks
- Prompt injection detection
- Tool poisoning detection
- Deep visibility reports
Topics: Inferred · not functionally tested
Built with & integrations
- Cursor
- commit a73c55cae00c · since Oct 2026
Trust & compliance
Indexing history
2What PulseGate has recorded for this listing
- Indexed7 Oct · 12:14 UTCsecurity-scanner-deepsleuth-mcp seen via PyPI Bulk EnumeratorSource: PyPI Bulk Enumerator · Open
Frequently asked questions about Deepsleuth
- What is Deepsleuth?
- Inferred · not functionally tested: Deepsleuth focuses on detecting security risks such as prompt injection and tool poisoning in MCP servers without relying on an LLM. It is catalogued under AI & LLM security on PulseGate.
- Who is Deepsleuth for?
- Inferred · not functionally tested: Deepsleuth is an open-source project built for developers and security teams building or auditing MCP servers.
- Does Deepsleuth have a free plan?
- Basis unknown · not verified: Yes — Deepsleuth is open source under the Apache-2.0 license and free to use.
- What platforms does Deepsleuth run on?
- Basis unknown · not verified: Deepsleuth runs on the command line. It can also be self-hosted.
- Is Deepsleuth still maintained?
- PulseGate's liveness check found it on 7 Oct 2026. Its GitHub repository shows 138 commits in the last 90 days.
- Who makes Deepsleuth?
- Deepsleuth is developed by DeepSleuth.
- When did Deepsleuth launch?
- Deepsleuth first shipped in 2025.
- Is Deepsleuth open source?
- Basis unknown · not verified: Yes — Deepsleuth is open source under the Apache-2.0 license, developed on GitHub.
Similar projects
Closest matches by what these projects do