G8KEPR
A Free Scanner as the Front Door
Part 22 of the thread Building G8KEPR
- The plan is a free MCP security CLI scanner as G8KEPR's front door. It hasn't shipped; the docs list it with roadmap status.
- People running MCP servers often can't easily answer a basic question: what can my agents actually do, and has any of it changed?
- Giving something useful away lets people judge the thinking behind G8KEPR before they're asked to trust it with anything.
- A free tool that's actually useful earns more trust than any amount of sales copy.
Let me say this at the top so nobody has to read between the lines: the free scanner in this post doesn't exist yet. It's a plan. The G8KEPR docs list the CLI with roadmap status, and I've mentioned it in passing in a couple of earlier posts. This is the longer version of why it's the plan.
The idea in one sentence
A free, command-line MCP security scanner that someone running MCP servers can use on their own setup, without buying anything, as the front door to G8KEPR.
A CLI, if the term's unfamiliar, is a command-line tool: you run it from a terminal rather than clicking around a web page. For the people I have in mind, that's usually the most natural way to try something.
Who it's for
The Model Context Protocol, MCP, is the standard way AI agents connect to tools: a database lookup, a file system, a ticketing system, a code repository. An MCP server offers a set of tools, each with a description the model reads to decide when and how to use it. I went through how that works, and how it can be abused, in the tool poisoning post.
MCP adoption has been fast, and fast adoption tends to outrun the security thinking around it. A team connects a few servers to get something working, then a few more, and before long agents have access to a lot of tools that nobody sat down and reviewed together.
So the person I'm picturing is someone who runs MCP servers, or is responsible for agents that use them, and has a slightly uneasy feeling they can't quite put numbers to.
The questions it should help answer
I'm not going to promise features for something that isn't built. What I can describe is the problem it's aimed at, which comes down to a few questions that are harder to answer than they should be:
- What can my agents actually reach? Not what you think you connected. What's really exposed.
- Is anything more powerful than it needs to be? Tools that can write when reading would do, or that reach further than the job requires.
- Has anything changed since I looked? Tool definitions can change after they're approved, which is the whole idea behind a rug pull.
If the scanner helps someone answer those for their own setup, it's done its job, whether or not they ever look at the rest of G8KEPR.
Why give it away
There are a few reasons, and they're mostly about trust.
Security buyers are right to be skeptical. G8KEPR asks to sit in the path of sensitive traffic. That's a big ask from a product built by one person. A free tool lets someone judge the quality of the thinking with nothing at stake. If the scanner is sloppy, they've learned something. If it's sharp, they've learned something too.
Useful beats persuasive. I could write a lot of copy about why MCP security matters. Or I could hand someone a tool that shows them something about their own environment. The second one does the arguing for me.
It meets people where the problem starts. Most people don't wake up wanting a runtime security layer. They wake up wondering whether the thing they wired together last month is safe. A scanner answers the first question. G8KEPR is for the questions that come after it, like watching tool calls as they happen and connecting signals across a whole request.
It's a better front door than a sales call. Especially for engineers, who would generally rather try something than talk about it.
How it fits with keeping the core closed
I went back and forth on open source in September and ended up keeping G8KEPR proprietary, because the correlation engine is the part with commercial value. A free scanner doesn't contradict that. It's a separate, useful thing given away on purpose, not the engine with a different price tag.
What happens next
When it ships, I'll write it up properly here, with what it actually does rather than what I hope it will. Until then, this post is the honest status: it's the plan, it's on the roadmap, and I think it's the right way in.
If you run MCP servers and have opinions about what a scanner like this should show you, I'd like to hear them. g8kepr.com is the place to start.