injection-detector

Formally-verified injection/exfiltration detector for AI agents (MCP-02).

¿Debería usar esto?

Calidad y seguridad

A
Calidad de la descripción
100%
Integridad del esquema
95%
Calidad de los nombres
80%
Riesgo de envenenamiento
100%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~696Tokens (definiciones de herramientas)
~3.2 KBTamaño de respuesta típico
Impacto moderado en la atención (0.54% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "injection-detector": {
      "url": "https://mcp.viridis-security.com/mcp"
    }
  }
}

Puntos de conexión remotos

https://mcp.viridis-security.com/mcpstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (2)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
⚪detect_injection(input, context, certainty, agentId)

Screen untrusted input for prompt/tool injection, exfiltration, and obfuscation before an agent consumes it. Returns a verdict (clean|suspicious|attack), probability, bits-at-risk (upper bound on adversarial capture per the Adversarial Landauer bound), matched canon patterns, and a recommended action (allow|sanitize|reject|escalate). Backed by Aristotle-verified theorems T-IB-02/T-IB-06/T-IB-01.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "input": {
      "type": "string",
      "description": "The untrusted text/data to screen.",
      "minLength": 1,
      "maxLength": 200000
    },
    "context": {
      "type": "string",
      "description": "Optional: the agent's role/system prompt; helps calibrate."
    },
    "certainty": {
      "type": "string",
      "enum": [
        "quick",
        "standard",
        "premium"
      ],
      "description": "Operating point. Default standard."
    },
    "agentId": {
      "type": "string",
      "description": "Optional: for MCP-01 envelope cross-check."
    }
  },
  "required": [
    "input"
  ],
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "verdict": {
      "type": "string",
      "enum": [
        "clean",
        "suspicious",
        "attack"
      ]
    },
    "probability": {
      "type": "number"
    },
    "bitsAtRisk": {
      "type": "number"
    },
    "operatingPoint": {
      "type": "object"
    },
    "matchedPatterns": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "recommendedAction": {
      "type": "string",
      "enum": [
        "allow",
        "sanitize",
        "reject",
        "escalate"
      ]
    },
    "signals": {
      "type": "object"
    },
    "explainabilityToken": {
      "type": "string"
    },
    "backedBy": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  },
  "required": [
    "verdict",
    "probability",
    "bitsAtRisk",
    "recommendedAction"
  ]
}
🟢detect_trace_tool_policy(trace, traces, targetName)

Analyze an agent trace for the Gray Swan Wave 16 class: untrusted retrieved/tool output causing a tool call outside the user-declared per-turn allowlist. Returns trace counts, unauthorized tool-call evidence, canon mapping VC-AI-TOOL-0001, and claim-boundary guardrails. Backed by T-IB-25/T-IB-29/T-IB-36.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "trace": {
      "type": "object",
      "description": "Single agent trace with user_prompt, allowed_tools, and events[].",
      "additionalProperties": true
    },
    "traces": {
      "type": "array",
      "description": "Optional batch of agent traces.",
      "items": {
        "type": "object",
        "additionalProperties": true
      }
    },
    "targetName": {
      "type": "string",
      "description": "Optional display name for the assessed target."
    }
  },
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "mode": {
      "type": "string",
      "enum": [
        "trace_tool_policy_probe"
      ]
    },
    "verdict": {
      "type": "string",
      "enum": [
        "clean",
        "suspicious",
        "attack"
      ]
    },
    "probability": {
      "type": "number"
    },
    "recommendedAction": {
      "type": "string",
      "enum": [
        "allow",
        "sanitize",
        "reject",
        "escalate"
      ]
    },
    "canonId": {
      "type": "string"
    },
    "theoremRefs": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "customerSystemProved": {
      "type": "boolean"
    },
    "claimBoundary": {
      "type": "string"
    },
    "summary": {
      "type": "object"
    },
    "traces": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "reviewPriority": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "explainabilityToken": {
      "type": "string"
    }
  },
  "required": [
    "mode",
    "verdict",
    "recommendedAction",
    "summary",
    "reviewPriority"
  ]
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada2 herramientas
verificadoversión no registrada2 herramientas