cloakcheck
Scan a page for hidden prompt-injection payloads targeting AI agents.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"cloakcheck": {
"url": "https://cloakcheck-wheat.vercel.app/api/mcp"
}
}
}Remote-Endpunkte
https://cloakcheck-wheat.vercel.app/api/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (1)
🟢check_page_for_injection(url)
Scan a single web page for content planted to hijack an AI agent reading it -- invisible unicode (zero-width chars, the unicode 'tag' block used for steganographic prompt injection), CSS-hidden instruction text, and instruction-shaped language in alt/title/aria-label attributes a human would never read. Does NOT judge whether visible body text is safe -- only content hidden from normal human reading flow is flagged, so a page that legitimately discusses prompt injection won't false-positive on itself. Call this before an autonomous shopping/browsing agent acts on a page's content (add to cart, follow instructions found on the page, etc).
Eingabe-Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The full URL (http:// or https://) of the page to scan"
}
},
"required": [
"url"
]
}Community
Nachweis