Capture the evidence.
Resolve the artifact. Hash its contents. Normalize the tool surface. Record what static analysis can see.
Know when an MCP server, agent skill or tool changes after you trusted it.
7c9e 4a21 8fd0 b631READ_ONLY · PINNED7c9e 9f02 8fd0 b631+ READ_ENV + WRITE_LOCAL_FILEInspect a component’s declared surface and static capability indicators. No signup required.
The component you approved yesterday can be different today. Keep the approval. Detect the difference.
Resolve the artifact. Hash its contents. Normalize the tool surface. Record what static analysis can see.
Inspect the report and approve a known state. Your approved baseline remains unchanged until you replace it.
Scheduled checks compare new evidence with your baseline. Material changes arrive with a concise diff and a next step.
A new capability matters more than another opaque security score. DriftSeal shows the old value, new value, location, confidence and reason to review.
Understand tool rug pulls ↗// Approved baseline − capabilities: ["NETWORK_OUTBOUND"] // Current observation + capabilities: ["NETWORK_OUTBOUND", + "READ_LOCAL_FILE", "READ_ENV"]
One watch = one monitored component.
No per-scan billing. No sales call.
Inspect a component before trusting it.
Know when trusted components change.
Know when trusted components change.
Know when trusted components change.
USD, monthly. Manage or cancel in your billing portal. Monitoring frequency depends on target availability. Taxes may apply.
Run private analysis locally. Commit a baseline. Gate CI on the severity you choose. Cloud signup is optional for one-time analysis.
Read the CLI quick start ↗# Scan locally. No component execution. driftseal scan ./agent-tools --json # Approve, then compare. driftseal baseline ./agent-tools driftseal diff baseline.json current.json # Keep watch on a public package. driftseal watch @scope/mcp-server