TrustScan
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"trust-scan": {
"url": "https://trust-scan-production.up.railway.app/mcp/"
}
}
}Remote endpoints
https://trust-scan-production.up.railway.app/mcp/streamable-httpWhat it can do
Tool inventory
Tools (4)
🟢trust_scan_server(path, package_name)
Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
Input Schema
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "directory or file path to scan (on the TrustScan host)"
},
"package_name": {
"default": "",
"type": "string",
"description": "package name for typosquat detection (e.g. \"mcp-server\")"
}
},
"required": [
"path"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢trust_scan_file(filepath)
Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
Input Schema
{
"type": "object",
"properties": {
"filepath": {
"type": "string",
"description": "absolute path of the file to scan"
}
},
"required": [
"filepath"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢skills_list_tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢read_skill(uri)
Read a product skill file by its skill:// URI.
Input Schema
{
"type": "object",
"properties": {
"uri": {
"type": "string",
"description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
}
},
"required": [
"uri"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}Community
Evidence