cloakcheck

Scan a page for hidden prompt-injection payloads targeting AI agents.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
100%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~184Tokens (tool definitions)
~438 BTypical response size
Minimal attention impact (0.14% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "cloakcheck": {
      "url": "https://cloakcheck-wheat.vercel.app/api/mcp"
    }
  }
}

Remote endpoints

https://cloakcheck-wheat.vercel.app/api/mcpstreamable-http

What it can do

Tool inventory

Tools (1)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢check_page_for_injection(url)

Scan a single web page for content planted to hijack an AI agent reading it -- invisible unicode (zero-width chars, the unicode 'tag' block used for steganographic prompt injection), CSS-hidden instruction text, and instruction-shaped language in alt/title/aria-label attributes a human would never read. Does NOT judge whether visible body text is safe -- only content hidden from normal human reading flow is flagged, so a page that legitimately discusses prompt injection won't false-positive on itself. Call this before an autonomous shopping/browsing agent acts on a page's content (add to cart, follow instructions found on the page, etc).

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The full URL (http:// or https://) of the page to scan"
    }
  },
  "required": [
    "url"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded1 tools
verifiedversion not recorded1 tools