TrustScan
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"trust-scan": {
"url": "https://trust-scan-production.up.railway.app/mcp/"
}
}
}Remote-Endpunkte
https://trust-scan-production.up.railway.app/mcp/streamable-httpWas es kann
Tool-Inventar
Tools (4)
🟢trust_scan_server(path, package_name)
Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
Eingabe-Schema
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "directory or file path to scan (on the TrustScan host)"
},
"package_name": {
"default": "",
"type": "string",
"description": "package name for typosquat detection (e.g. \"mcp-server\")"
}
},
"required": [
"path"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢trust_scan_file(filepath)
Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
Eingabe-Schema
{
"type": "object",
"properties": {
"filepath": {
"type": "string",
"description": "absolute path of the file to scan"
}
},
"required": [
"filepath"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢skills_list_tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢read_skill(uri)
Read a product skill file by its skill:// URI.
Eingabe-Schema
{
"type": "object",
"properties": {
"uri": {
"type": "string",
"description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
}
},
"required": [
"uri"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}Community
Nachweis