AIShield Security Scanner
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
¿Debería usar esto?
Calidad y seguridad
Hallazgos (4)
- LOWen aishield_scan
- LOWen aishield_prompt_check
- LOWen aishield_banned_words
- LOWen aishield_vertical_risk
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"aishield": {
"command": "npx",
"args": [
"aishield-mcp-server"
]
}
}
}Paquetes ejecutables
4.3.0stdioPuntos de conexión remotos
https://aishield.tools/api/v1/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (10)
⚪aishield_scan(source_url, tool_type, name)
OWASP MCP Top 10 aligned security scan — 235 rules, 5-dimension scoring
Esquema de entrada
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
},
"tool_type": {
"type": "string",
"enum": [
"mcp",
"skill",
"gpt",
"prompt"
],
"default": "mcp"
},
"name": {
"type": "string",
"description": "Tool name"
}
},
"required": [
"source_url"
]
}🟢aishield_guardrail(source_url, auto_block)
Pre-install safety check — pass/block verdict
Esquema de entrada
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
},
"auto_block": {
"type": "boolean",
"default": true
}
},
"required": [
"source_url"
]
}🟢aishield_prompt_check(prompt)
Prompt injection detection — Chinese + English
Esquema de entrada
{
"type": "object",
"properties": {
"prompt": {
"type": "string",
"description": "Prompt text to check (min 10 chars)"
}
},
"required": [
"prompt"
]
}⚪aishield_banned_words(text, platform)
Chinese banned words detection — 6 platform rules
Esquema de entrada
{
"type": "object",
"properties": {
"text": {
"type": "string",
"description": "Text to check"
},
"platform": {
"type": "string",
"enum": [
"douyin",
"xiaohongshu",
"wechat",
"weibo",
"bilibili",
"kuaishou",
"all"
],
"default": "all"
}
},
"required": [
"text"
]
}🟢aishield_rug_pull(source_url)
Rug pull detection — check if a tool has removed security code or added suspicious changes in recent commits
Esquema de entrada
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
}
},
"required": [
"source_url"
]
}🟢aishield_handshake(source_url)
MCP handshake verification — analyze MCP config, detect npx auto-install, sensitive env vars, oversized tool descriptions, and attempt HTTP handshake
Esquema de entrada
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
}
},
"required": [
"source_url"
]
}⚪aishield_digest(configs, scan_result, source_url, max_findings)
Compact trust digest (aishield-digest/v1) — a few hundred bytes plus a content fingerprint, so an agent can answer 'can I trust this?' every turn without re-pulling the full report. Accepts {configs} (static analysis only), {scan_result}, or {source_url}. The returned `risk` is never lighter than the worst finding actually present (a config with high findings is never labelled 'safe'), and no plaintext credential is ever echoed back.
Esquema de entrada
{
"type": "object",
"properties": {
"configs": {
"type": "object",
"description": "{path: file content} MCP client config map — static analysis, no command in the config is ever executed"
},
"scan_result": {
"type": "object",
"description": "An existing scan result to compress"
},
"source_url": {
"type": "string",
"description": "GitHub repo URL — return the current trust verdict as a digest"
},
"max_findings": {
"type": "integer",
"minimum": 0,
"maximum": 20,
"default": 3,
"description": "How many top findings to include"
}
}
}⚪aishield_vertical_risk(text, domain)
Vertical-industry risk scan — detect high-risk claims for finance/medical/gov sectors (unlicensed diagnosis, illegal medical device, financial over-promise, etc.)
Esquema de entrada
{
"type": "object",
"properties": {
"text": {
"type": "string",
"description": "Text content to scan"
},
"domain": {
"type": "string",
"enum": [
"finance",
"medical",
"government"
],
"default": "finance",
"description": "Vertical domain"
}
},
"required": [
"text"
]
}🟢agent_register(agent_name, capabilities, owner)
Agent-First one-click onboarding — register as an Agent, get DID + API Key + quick start guide in a single call
Esquema de entrada
{
"type": "object",
"properties": {
"agent_name": {
"type": "string",
"description": "Agent name (required)"
},
"capabilities": {
"type": "array",
"items": {
"type": "string"
},
"description": "Capability list, e.g. [\"scan\", \"monitor\"]"
},
"owner": {
"type": "string",
"description": "Owner identifier"
}
},
"required": [
"agent_name"
]
}⚪agent_quick_scan(tool_name, tool_description, source_url)
Agent-First quick scan — scan a tool by name and description, no source URL required
Esquema de entrada
{
"type": "object",
"properties": {
"tool_name": {
"type": "string",
"description": "Tool name (required)"
},
"tool_description": {
"type": "string",
"description": "Tool description (required)"
},
"source_url": {
"type": "string",
"description": "Optional GitHub repo URL for deep scan"
}
},
"required": [
"tool_name",
"tool_description"
]
}Comunidad
Evidencia