TrustScan
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"trust-scan": {
"url": "https://trust-scan-production.up.railway.app/mcp/"
}
}
}Puntos de conexión remotos
https://trust-scan-production.up.railway.app/mcp/streamable-httpQué puede hacer
Inventario de herramientas
Herramientas (4)
🟢trust_scan_server(path, package_name)
Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
Esquema de entrada
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "directory or file path to scan (on the TrustScan host)"
},
"package_name": {
"default": "",
"type": "string",
"description": "package name for typosquat detection (e.g. \"mcp-server\")"
}
},
"required": [
"path"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢trust_scan_file(filepath)
Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
Esquema de entrada
{
"type": "object",
"properties": {
"filepath": {
"type": "string",
"description": "absolute path of the file to scan"
}
},
"required": [
"filepath"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢skills_list_tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
Esquema de entrada
{
"type": "object",
"properties": {},
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}🟢read_skill(uri)
Read a product skill file by its skill:// URI.
Esquema de entrada
{
"type": "object",
"properties": {
"uri": {
"type": "string",
"description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
}
},
"required": [
"uri"
],
"additionalProperties": false
}Esquema de salida
{
"type": "object",
"additionalProperties": true
}Comunidad
Evidencia