injection-detector
Formally-verified injection/exfiltration detector for AI agents (MCP-02).
使うべきか
品質と安全性
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"injection-detector": {
"url": "https://mcp.viridis-security.com/mcp"
}
}
}リモートエンドポイント
https://mcp.viridis-security.com/mcpstreamable-httpできること
ツール一覧
ツール(2)
⚪detect_injection(input, context, certainty, agentId)
Screen untrusted input for prompt/tool injection, exfiltration, and obfuscation before an agent consumes it. Returns a verdict (clean|suspicious|attack), probability, bits-at-risk (upper bound on adversarial capture per the Adversarial Landauer bound), matched canon patterns, and a recommended action (allow|sanitize|reject|escalate). Backed by Aristotle-verified theorems T-IB-02/T-IB-06/T-IB-01.
入力スキーマ
{
"type": "object",
"properties": {
"input": {
"type": "string",
"description": "The untrusted text/data to screen.",
"minLength": 1,
"maxLength": 200000
},
"context": {
"type": "string",
"description": "Optional: the agent's role/system prompt; helps calibrate."
},
"certainty": {
"type": "string",
"enum": [
"quick",
"standard",
"premium"
],
"description": "Operating point. Default standard."
},
"agentId": {
"type": "string",
"description": "Optional: for MCP-01 envelope cross-check."
}
},
"required": [
"input"
],
"additionalProperties": false
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"type": "string",
"enum": [
"clean",
"suspicious",
"attack"
]
},
"probability": {
"type": "number"
},
"bitsAtRisk": {
"type": "number"
},
"operatingPoint": {
"type": "object"
},
"matchedPatterns": {
"type": "array",
"items": {
"type": "string"
}
},
"recommendedAction": {
"type": "string",
"enum": [
"allow",
"sanitize",
"reject",
"escalate"
]
},
"signals": {
"type": "object"
},
"explainabilityToken": {
"type": "string"
},
"backedBy": {
"type": "array",
"items": {
"type": "string"
}
}
},
"required": [
"verdict",
"probability",
"bitsAtRisk",
"recommendedAction"
]
}🟢detect_trace_tool_policy(trace, traces, targetName)
Analyze an agent trace for the Gray Swan Wave 16 class: untrusted retrieved/tool output causing a tool call outside the user-declared per-turn allowlist. Returns trace counts, unauthorized tool-call evidence, canon mapping VC-AI-TOOL-0001, and claim-boundary guardrails. Backed by T-IB-25/T-IB-29/T-IB-36.
入力スキーマ
{
"type": "object",
"properties": {
"trace": {
"type": "object",
"description": "Single agent trace with user_prompt, allowed_tools, and events[].",
"additionalProperties": true
},
"traces": {
"type": "array",
"description": "Optional batch of agent traces.",
"items": {
"type": "object",
"additionalProperties": true
}
},
"targetName": {
"type": "string",
"description": "Optional display name for the assessed target."
}
},
"additionalProperties": false
}出力スキーマ
{
"type": "object",
"properties": {
"mode": {
"type": "string",
"enum": [
"trace_tool_policy_probe"
]
},
"verdict": {
"type": "string",
"enum": [
"clean",
"suspicious",
"attack"
]
},
"probability": {
"type": "number"
},
"recommendedAction": {
"type": "string",
"enum": [
"allow",
"sanitize",
"reject",
"escalate"
]
},
"canonId": {
"type": "string"
},
"theoremRefs": {
"type": "array",
"items": {
"type": "string"
}
},
"customerSystemProved": {
"type": "boolean"
},
"claimBoundary": {
"type": "string"
},
"summary": {
"type": "object"
},
"traces": {
"type": "array",
"items": {
"type": "object"
}
},
"reviewPriority": {
"type": "array",
"items": {
"type": "object"
}
},
"explainabilityToken": {
"type": "string"
}
},
"required": [
"mode",
"verdict",
"recommendedAction",
"summary",
"reviewPriority"
]
}コミュニティ
エビデンス