
Point-in-time MCP grades find risk; runtime firewalls enforce policy on tool calls. Andrax mcpgrade-1.4.0 vs Guard mcpgrade-2.0.0 — no score equating.
Andrax Pentester is not Android ANDRAX — we are a cybersecurity education site and MCP security grader at andraxpentester.in. Clear the name collision in one minute.
6 min read
An exhaustive analysis of critical security flaws in AI agent MCP bridges and eBPF kernel instrumentation, featuring empirical exploitation mechanics, detection engineering signatures (Sigma/
5 min read
You scan an MCP server once, land a letter grade, wire it into the agent, and move on. That workflow is common — and incomplete. A point-in-time grade does not watch the next tools/list or the next tools/call. Definitions can change after you approved them. Policies you meant to enforce never run because nothing sits on the live path.
This page is Hub 3 for Andrax Pentester’s MCP firewall / runtime cluster and BOFU #1: a decision guide, not a corpus report. Grade finds risk; runtime enforces policy. An A–F letter is not a gate on live tool traffic.
Grade-only scanner / index. A pre-connect or periodic assessment that produces a letter grade, scorecard, or report. Andrax Pentester’s public scanner surface uses mcpgrade-1.4.0: 39 checks, with ~5,319 servers graded as stated on the Andrax homepage as of 2026-09-17. The graded directory is the inventory UX for those results.
Runtime firewall / gateway / policy layer. A control that inspects or mediates live MCP traffic and can allow, deny, or audit. SentinelAgent Guard’s published runtime rubric is mcpgrade-2.0.0: 22 deterministic checks across five layers (L0–L3 + audit trail), as stated on the Guard product page as of 2026-09-17.
One-sentence fence: A letter grade is not a Guard runtime score. Do not equate them. Shared lineage is fine to mention; product surfaces still publish different versions and check counts until a single public methodology page lands.
Grade-only scanners earn their keep. Treat them fairly.
Triage before connect. Before an agent trusts a new server, a grade answers “what failed on this snapshot?” faster than reading every tool schema by hand. That is the job of a pre-connect assessment.
Signals, not silver bullets. Public scanners surface auth, TLS, and poisoning-related signals according to their own methodologies. Andrax’s homepage-stated rubric (mcpgrade-1.4.0, 39 checks) is one such method. Other indexes use different lenses — blast radius from declared tools, catalog hygiene, and so on. Cite each product’s public method; do not invent a merged scoreboard.
Directory and inventory hygiene. A browsable graded catalog (/mcp-servers) helps teams see what is already assessed and what still needs a look. Discovery at catalog scale is a scanner strength.
CI and pre-merge gates. Point-in-time checks belong in pipelines that block merge when a known-bad snapshot appears. For Andrax, that means scanner mcpgrade-1.4.x, not Guard’s runtime mcpgrade-2.0.0. Different product, different output, different moment in the lifecycle.
Grades communicate risk. They do not sit on the wire.
A letter does not:
tools/call.If your threat model includes post-approval mutation, untrusted third-party MCP servers, or least-privilege requirements for agent actions, a grade-only stack leaves residual risk by design.
Runtime MCP security sits where traffic actually flows. Guard’s public positioning describes three deployment patterns: hosted gateway, embedded SDK, and sidecar CLI. The point is the same in each case: inspect or mediate messages so policy can run before a risky call completes.
At call time, a runtime layer can detect and block classes of abuse that a yesterday’s scan only flagged — including tool-poisoning themes and mutation-after-approval fingerprinting (Guard maps related checks under its published runtime rubric; see the Guard product page for current check names and layering). It can also retain an audit trail of agent actions for review and compliance narratives.
That is the complementary job: enforce policy, not replace thoughtful server hardening or least privilege on the server itself.
If you only need a free, point-in-time view, grade on Andrax first. When production agents need continuous allow/deny/audit on MCP traffic, Guard Pro is the commercial path: sign up for Guard Pro.
| Dimension | Grade-only scanners / indexes | Guard runtime (firewall) |
|---|---|---|
| Timing | Point-in-time / periodic | Continuous / per-message or per-call (as product states) |
| Output | Letter grade / scorecard / report | Allow · deny · audit decisions |
| Rubric (Andrax / Guard) | Andrax public: mcpgrade-1.4.0, 39 checks (homepage, as of 2026-09-17) | Guard: mcpgrade-2.0.0, 22 checks / 5 layers (product page, as of 2026-09-17) |
| Primary job | Find / communicate risk | Enforce policy |
| Typical user moment | Before connect; inventory | Production agent path |
| Changes after approval | Re-scan required to notice | Can fingerprint / block mutation (per Guard public claims) |
| Cost model | Often free scan / index | Free tier → paid (all 22 checks on free for one server; paid adds servers, history, seats, compliance — not “more detection”) |
| Does not replace | Runtime controls | Server hardening + least privilege |
Category honesty (peers): Other runtime proxies exist — for example PolicyLayer-style MCP gateways that apply call-time policy. Indexes such as AxioRank’s MCP Security Index publish blast-radius grades from declared tools; that is a read-only index lens, not a vulnerability scanner and not a firewall. Name peers by their public methodology. No crowning “#1.”
A scanner-only approach can be appropriate when:
Even then, document the residual risk: the grade is a snapshot. Re-grade when the server or your trust decision changes.
Prefer runtime enforcement when:
In those cases, treating an A grade as a permanent gate is the failure mode this article opened with.
mcpgrade-1.4.0). Start at the homepage or browse the directory.mcpgrade-2.0.0) — hosted gateway, SDK, or sidecar as fits your stack. Free tier runs all 22 checks on one server; Pro expands capacity and operational features.Brand note: Andrax Pentester is an MCP security / grading product line, distinct from the older Android pentest distribution sometimes also called “ANDRAX.” See Andrax Pentester vs Android ANDRAX if you landed here from a brand search.
More explainers live on the articles index.
Indexes / grades. Multiple public indexes grade or score MCP servers. Some emphasize poisoning and auth signals; others emphasize blast radius from declared tool capabilities (AxioRank’s public framing is blast-radius / read-only index — not vuln-scan, not firewall). Andrax publishes letter grades from mcpgrade-1.4.0 on a dated corpus. Use indexes for triage and comparison of methods, not as a substitute for runtime control.
Runtime / gateway peers. PolicyLayer and other OSS or commercial MCP firewalls / proxies sit in the same category job as Guard: mediate or inspect live traffic. Compare deployment model, policy expressiveness, and audit story from each vendor’s public docs. This page does not rank them.
We do not claim to be the #1 MCP scanner or firewall. We explain tradeoffs and cite public methods.
CVE-2025-54136 is associated with the Cursor MCPoison class: a config / trust / re-approval problem in how clients handle MCP configuration. Keep that label distinct from informal “rug pull” metaphors about tool-definition swaps after approval. Both themes matter for defenders; they are not the same title. Body discussions of mutation-after-approval should not rename the CVE. For runtime mapping of mutation themes, rely on Guard’s published checks on the product page — not on conflating CVE names in H1s or meta tags.
No. Grades assess a point-in-time (or periodic) snapshot. Firewalls and runtime policy layers enforce allow/deny/audit on live MCP traffic. A letter grade does not block tools/call.
The public Andrax scanner states mcpgrade-1.4.0 with 39 checks and on the order of 5,319 graded servers, as shown on andraxpentester.in as of 2026-09-17. Re-check the homepage before citing newer counters.
Guard’s product page states runtime rubric mcpgrade-2.0.0 with 22 checks across five layers (L0–L3 + audit trail), as of 2026-09-17. That score is not interchangeable with an Andrax letter grade.
Sometimes — for low-risk, tightly constrained, or non-executing setups. If tool definitions can change after approval, or agents execute privileged tools, a scanner-only path leaves residual risk until you re-scan or add runtime enforcement.
No. We describe what grades do well, what runtime adds, and we cite public methodologies. No invented volumes or crown claims.
Start with a free Andrax grade (mcpgrade-1.4.0). If you need policy enforced on live MCP traffic, use Guard Pro (mcpgrade-2.0.0 runtime).
Start with a free Andrax grade (mcpgrade-1.4.0) to see point-in-time risk on the Andrax homepage or in the /mcp-servers directory.
When you need policy enforced on live MCP traffic, use Guard runtime (mcpgrade-2.0.0):
Grades find risk. Runtime enforces policy. Free grading stays free; free Guard still runs all 22 checks on one server. Upgrade when you need more servers, history, seats, or compliance features — not because detection was locked behind a paywall.
Share this article
Master Model Context Protocol (MCP) security auditing. Build automated Python static AST and JSON-Schema analyzers to detect indirect prompt injection and tool poisoning.
5 min read
Sign in to leave a comment.