DropEngine
Prompt-Injection Firewall · PAID MCP TOOL

scan_content

Scans untrusted content before an agent adds it to context, follows its instructions, or acts on it.

When an agent should call it

Deterministic local analysis returns a structured risk report and sanitized plain text where possible; it does not call an LLM or store raw content.

Input: Text, HTML, email, document text, API response, or tool output up to 100,000 characters by default

Price: $0.005 USDC per call, paid in USDC via x402 on Base.

MCP connection: one-time setup, then call scan_content on each needed workflow.

Direct HTTP resource: https://mcp.dropenginehq.com/api/scan-content

Example input

{
  "content": "Product information: price USD 25, available in stock.",
  "content_type": "text"
}

Representative output

This is an example of the response shape, not a live result. Current registry data and provider configuration can change the values.

{
  "safe": true,
  "risk_score": 0,
  "risk_level": "low",
  "recommendation": "allow",
  "prompt_injection_detected": false,
  "data_exfiltration_risk": false,
  "credential_theft_risk": false,
  "tool_manipulation_risk": false,
  "instruction_override_risk": false,
  "detected_patterns": [],
  "requested_actions": [],
  "sanitized_content": "The page has normal product information and pricing.",
  "sources": [],
  "cached": false,
  "degraded": false,
  "scanned_at": "2026-09-28T00:00:00.000Z"
}

Each call requests payment for this tool only. The agent receives a structured result and decides what to do next. Check the limits above before acting on risk, market, freshness, or availability results.

MCP endpoint: https://mcp.dropenginehq.com/api/paid-mcp