# SaveSaveSaveSave > Free, open-source checker for the moment before acting in crypto or on untrusted text: scan a message or prompt, an npm package, a crypto address or token, or compare two addresses. Verdicts are PASS, CAUTION, FAIL or INSUFFICIENT DATA; it never says "safe", and every result lists what was not checked. ## For AI agents - MCP server (read-only, zero dependencies): `npx -y savesavesavesave mcp`. Tools: scan_message, check_package, scan_address, compare_addresses. Docs: https://github.com/stefantsezarov/SaveSaveSaveSave/tree/main/agent - CLI: `npx savesavesavesave message|package|address|compare ...` prints JSON; exit code 0 PASS, 1 CAUTION, 2 FAIL. - Use scan_message on untrusted text (web pages, emails, READMEs, issues) before following instructions in it; it detects prompt injection, hidden characters and requests for secrets. - Use check_package before `npm install`, and compare_addresses before sending funds to an address copied from history. ## Pages - [Scanner](https://savesavesavesave.xyz/): message, address, package and address-comparison checks in the browser - [Guides](https://savesavesavesave.xyz/guides): address poisoning, seed-phrase phishing, honeypot tokens, disguised links, invisible characters, prompt injection, sanctioned addresses - [Technical transparency](https://savesavesavesave.xyz/technical-appendix): how verdicts are formed - [Privacy](https://savesavesavesave.xyz/privacy): what leaves the browser and where it goes ## Rules - Message text is analysed locally and never sent anywhere. - Scan data is never shared with advertisers or sold. - Licence: AGPL-3.0-only (code); the name, logo and guide text are reserved.