AIShield Security Scanner

Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

使うべきか

品質と安全性

A
説明の品質
82%
スキーマの完全性
96%
命名の品質
80%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(4)

  • LOWTool 'aishield_scan' description lacks action verbaishield_scan 内
  • LOWTool 'aishield_prompt_check' description lacks action verbaishield_prompt_check 内
  • LOWTool 'aishield_banned_words' description lacks action verbaishield_banned_words 内
  • LOWTool 'aishield_vertical_risk' description lacks action verbaishield_vertical_risk 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~984トークン数(ツール定義)
~712 B一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 0.77%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "aishield": {
      "command": "npx",
      "args": [
        "aishield-mcp-server"
      ]
    }
  }
}

実行可能なパッケージ

npmaishield-mcp-server4.3.0stdio

リモートエンドポイント

https://aishield.tools/api/v1/mcpstreamable-http

できること

ツール一覧

ツール(10)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
⚪aishield_scan(source_url, tool_type, name)

OWASP MCP Top 10 aligned security scan — 235 rules, 5-dimension scoring

入力スキーマ

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    },
    "tool_type": {
      "type": "string",
      "enum": [
        "mcp",
        "skill",
        "gpt",
        "prompt"
      ],
      "default": "mcp"
    },
    "name": {
      "type": "string",
      "description": "Tool name"
    }
  },
  "required": [
    "source_url"
  ]
}
🟢aishield_guardrail(source_url, auto_block)

Pre-install safety check — pass/block verdict

入力スキーマ

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    },
    "auto_block": {
      "type": "boolean",
      "default": true
    }
  },
  "required": [
    "source_url"
  ]
}
🟢aishield_prompt_check(prompt)

Prompt injection detection — Chinese + English

入力スキーマ

{
  "type": "object",
  "properties": {
    "prompt": {
      "type": "string",
      "description": "Prompt text to check (min 10 chars)"
    }
  },
  "required": [
    "prompt"
  ]
}
⚪aishield_banned_words(text, platform)

Chinese banned words detection — 6 platform rules

入力スキーマ

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "description": "Text to check"
    },
    "platform": {
      "type": "string",
      "enum": [
        "douyin",
        "xiaohongshu",
        "wechat",
        "weibo",
        "bilibili",
        "kuaishou",
        "all"
      ],
      "default": "all"
    }
  },
  "required": [
    "text"
  ]
}
🟢aishield_rug_pull(source_url)

Rug pull detection — check if a tool has removed security code or added suspicious changes in recent commits

入力スキーマ

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    }
  },
  "required": [
    "source_url"
  ]
}
🟢aishield_handshake(source_url)

MCP handshake verification — analyze MCP config, detect npx auto-install, sensitive env vars, oversized tool descriptions, and attempt HTTP handshake

入力スキーマ

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    }
  },
  "required": [
    "source_url"
  ]
}
⚪aishield_digest(configs, scan_result, source_url, max_findings)

Compact trust digest (aishield-digest/v1) — a few hundred bytes plus a content fingerprint, so an agent can answer 'can I trust this?' every turn without re-pulling the full report. Accepts {configs} (static analysis only), {scan_result}, or {source_url}. The returned `risk` is never lighter than the worst finding actually present (a config with high findings is never labelled 'safe'), and no plaintext credential is ever echoed back.

入力スキーマ

{
  "type": "object",
  "properties": {
    "configs": {
      "type": "object",
      "description": "{path: file content} MCP client config map — static analysis, no command in the config is ever executed"
    },
    "scan_result": {
      "type": "object",
      "description": "An existing scan result to compress"
    },
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL — return the current trust verdict as a digest"
    },
    "max_findings": {
      "type": "integer",
      "minimum": 0,
      "maximum": 20,
      "default": 3,
      "description": "How many top findings to include"
    }
  }
}
⚪aishield_vertical_risk(text, domain)

Vertical-industry risk scan — detect high-risk claims for finance/medical/gov sectors (unlicensed diagnosis, illegal medical device, financial over-promise, etc.)

入力スキーマ

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "description": "Text content to scan"
    },
    "domain": {
      "type": "string",
      "enum": [
        "finance",
        "medical",
        "government"
      ],
      "default": "finance",
      "description": "Vertical domain"
    }
  },
  "required": [
    "text"
  ]
}
🟢agent_register(agent_name, capabilities, owner)

Agent-First one-click onboarding — register as an Agent, get DID + API Key + quick start guide in a single call

入力スキーマ

{
  "type": "object",
  "properties": {
    "agent_name": {
      "type": "string",
      "description": "Agent name (required)"
    },
    "capabilities": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Capability list, e.g. [\"scan\", \"monitor\"]"
    },
    "owner": {
      "type": "string",
      "description": "Owner identifier"
    }
  },
  "required": [
    "agent_name"
  ]
}
⚪agent_quick_scan(tool_name, tool_description, source_url)

Agent-First quick scan — scan a tool by name and description, no source URL required

入力スキーマ

{
  "type": "object",
  "properties": {
    "tool_name": {
      "type": "string",
      "description": "Tool name (required)"
    },
    "tool_description": {
      "type": "string",
      "description": "Tool description (required)"
    },
    "source_url": {
      "type": "string",
      "description": "Optional GitHub repo URL for deep scan"
    }
  },
  "required": [
    "tool_name",
    "tool_description"
  ]
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 10 件
検証済みバージョンは記録されていませんツール 9 件