cloakcheck
Scan a page for hidden prompt-injection payloads targeting AI agents.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"cloakcheck": {
"url": "https://cloakcheck-wheat.vercel.app/api/mcp"
}
}
}Puntos de conexión remotos
https://cloakcheck-wheat.vercel.app/api/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (1)
🟢check_page_for_injection(url)
Scan a single web page for content planted to hijack an AI agent reading it -- invisible unicode (zero-width chars, the unicode 'tag' block used for steganographic prompt injection), CSS-hidden instruction text, and instruction-shaped language in alt/title/aria-label attributes a human would never read. Does NOT judge whether visible body text is safe -- only content hidden from normal human reading flow is flagged, so a page that legitimately discusses prompt injection won't false-positive on itself. Call this before an autonomous shopping/browsing agent acts on a page's content (add to cart, follow instructions found on the page, etc).
Esquema de entrada
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The full URL (http:// or https://) of the page to scan"
}
},
"required": [
"url"
]
}Comunidad
Evidencia