TrustScan

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
83%
Naming quality
85%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~522Tokens (tool definitions)
~683 BTypical response size
Minimal attention impact (0.41% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "trust-scan": {
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}

Remote endpoints

https://trust-scan-production.up.railway.app/mcp/streamable-http

What it can do

Tool inventory

Tools (4)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢trust_scan_server(path, package_name)

Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.

Input Schema

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "directory or file path to scan (on the TrustScan host)"
    },
    "package_name": {
      "default": "",
      "type": "string",
      "description": "package name for typosquat detection (e.g. \"mcp-server\")"
    }
  },
  "required": [
    "path"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢trust_scan_file(filepath)

Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.

Input Schema

{
  "type": "object",
  "properties": {
    "filepath": {
      "type": "string",
      "description": "absolute path of the file to scan"
    }
  },
  "required": [
    "filepath"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢skills_list_tool

List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢read_skill(uri)

Read a product skill file by its skill:// URI.

Input Schema

{
  "type": "object",
  "properties": {
    "uri": {
      "type": "string",
      "description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
    }
  },
  "required": [
    "uri"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded4 tools
verifiedversion not recorded4 tools