triageshield
Verify a vuln report's file/line/function claims against a real GitHub repo.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"triageshield": {
"url": "https://triageshield.vercel.app/api/mcp"
}
}
}Remote-Endpunkte
https://triageshield.vercel.app/api/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (1)
🟢check_vuln_report(report, repo)
Verify a vulnerability report's concrete, checkable claims (file paths, `file.py:123` line citations, function names) against a real GitHub repo's current default-branch state. Does NOT judge whether the described vulnerability is real or exploitable -- it only checks whether the files/lines/functions cited actually exist, which is the exact 'AI slop' failure mode (hallucinated specifics) that makes up a real share of auto-generated vuln reports. A PLAUSIBLE verdict means the claims check out, not that the vulnerability is confirmed real.
Eingabe-Schema
{
"type": "object",
"properties": {
"report": {
"type": "string",
"description": "The vulnerability report text to check"
},
"repo": {
"type": "string",
"description": "A github.com/owner/name URL for the repo the report claims to be about"
}
},
"required": [
"report",
"repo"
]
}Community
Nachweis