security-preflight

Static MCP, source-code and injection-indicator checks with redacted signed receipts.

¿Debería usar esto?

Calidad y seguridad

B
Calidad de la descripción
90%
Integridad del esquema
67%
Calidad de los nombres
84%
Riesgo de envenenamiento
100%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Hallazgos (1)

  • LOWTool 'describe_agent' description lacks action verben describe_agent

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~754Tokens (definiciones de herramientas)
~1.2 KBTamaño de respuesta típico
Impacto moderado en la atención (0.59% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "security-preflight": {
      "url": "https://mcp.viridisconservation.com/security-preflight/mcp"
    }
  }
}

Puntos de conexión remotos

https://mcp.viridisconservation.com/security-preflight/mcpstreamable-http
https://mcp.viridis-security.com/security-preflight/mcpstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (5)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
⚪security_preflight(agent_id, manifest, subject_profile_sha256, policy, sample_inputs, ...)

Run a $1 static Security Preflight and return a signed receipt. New x402 payer wallets may receive the fleet-wide $0.01 introductory call. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "agent_id": {
      "title": "Agent Id",
      "type": "string"
    },
    "manifest": {
      "additionalProperties": true,
      "title": "Manifest",
      "type": "object"
    },
    "subject_profile_sha256": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "title": "Subject Profile Sha256"
    },
    "policy": {
      "anyOf": [
        {
          "additionalProperties": true,
          "type": "object"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "title": "Policy"
    },
    "sample_inputs": {
      "anyOf": [
        {
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "title": "Sample Inputs"
    },
    "payment_ref": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "title": "Payment Ref"
    },
    "request_id": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null,
      "title": "Request Id"
    }
  },
  "required": [
    "agent_id",
    "manifest"
  ],
  "title": "security_preflightArguments"
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "result": {
      "title": "Result",
      "type": "string"
    }
  },
  "required": [
    "result"
  ],
  "title": "security_preflightOutput"
}
⚪scan_source(agent_id, source)

$1 bounded inline VulnCanon source scan; indicators, not proven exploits. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "agent_id": {
      "title": "Agent Id",
      "type": "string"
    },
    "source": {
      "title": "Source",
      "type": "string"
    }
  },
  "required": [
    "agent_id",
    "source"
  ],
  "title": "scan_sourceArguments"
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "result": {
      "title": "Result",
      "type": "string"
    }
  },
  "required": [
    "result"
  ],
  "title": "scan_sourceOutput"
}
⚪screen_injection(agent_id, texts)

$1 batch of 1–20 text samples screened for deterministic injection markers. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "agent_id": {
      "title": "Agent Id",
      "type": "string"
    },
    "texts": {
      "items": {
        "type": "string"
      },
      "title": "Texts",
      "type": "array"
    }
  },
  "required": [
    "agent_id",
    "texts"
  ],
  "title": "screen_injectionArguments"
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "result": {
      "title": "Result",
      "type": "string"
    }
  },
  "required": [
    "result"
  ],
  "title": "screen_injectionOutput"
}
🟢get_security_receipt(receipt_id)

Read a previously issued public, input-redacted receipt.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "receipt_id": {
      "title": "Receipt Id",
      "type": "string"
    }
  },
  "required": [
    "receipt_id"
  ],
  "title": "get_security_receiptArguments"
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "result": {
      "title": "Result",
      "type": "string"
    }
  },
  "required": [
    "result"
  ],
  "title": "get_security_receiptOutput"
}
🟢describe_agent

Describe scope, evidence boundary, inputs, and outputs.

Esquema de entrada

{
  "type": "object",
  "properties": {},
  "title": "describe_agentArguments"
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "result": {
      "title": "Result",
      "type": "string"
    }
  },
  "required": [
    "result"
  ],
  "title": "describe_agentOutput"
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada5 herramientas
verificadoversión no registrada5 herramientas
verificadoversión no registrada5 herramientas
verificadoversión no registrada5 herramientas