TrustScan

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
83%
命名の品質
85%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~522トークン数(ツール定義)
~683 B一般的なレスポンスサイズ
注意への影響は最小限(128k コンテキストの 0.41%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "trust-scan": {
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}

リモートエンドポイント

https://trust-scan-production.up.railway.app/mcp/streamable-http

できること

ツール一覧

ツール(4)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢trust_scan_server(path, package_name)

Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.

入力スキーマ

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "directory or file path to scan (on the TrustScan host)"
    },
    "package_name": {
      "default": "",
      "type": "string",
      "description": "package name for typosquat detection (e.g. \"mcp-server\")"
    }
  },
  "required": [
    "path"
  ],
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "additionalProperties": true
}
🟢trust_scan_file(filepath)

Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.

入力スキーマ

{
  "type": "object",
  "properties": {
    "filepath": {
      "type": "string",
      "description": "absolute path of the file to scan"
    }
  },
  "required": [
    "filepath"
  ],
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "additionalProperties": true
}
🟢skills_list_tool

List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "additionalProperties": true
}
🟢read_skill(uri)

Read a product skill file by its skill:// URI.

入力スキーマ

{
  "type": "object",
  "properties": {
    "uri": {
      "type": "string",
      "description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
    }
  },
  "required": [
    "uri"
  ],
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "additionalProperties": true
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 4 件
検証済みバージョンは記録されていませんツール 4 件