Security audit for MCP servers and agent tool-chains. Read-only: it never executes the code it scans and never calls `tools/call`. ```bash toolfence https://github.com/owner/repo # scan a repo (extracts tools from source) toolfence ./path/to/server # scan a local checkout toolfence tools.json # scan a tools/list export