injection-detector

Formally-verified injection/exfiltration detector for AI agents (MCP-02).

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
95%
命名の品質
80%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~696トークン数(ツール定義)
~3.2 KB一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 0.54%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "injection-detector": {
      "url": "https://mcp.viridis-security.com/mcp"
    }
  }
}

リモートエンドポイント

https://mcp.viridis-security.com/mcpstreamable-http

できること

ツール一覧

ツール(2)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
⚪detect_injection(input, context, certainty, agentId)

Screen untrusted input for prompt/tool injection, exfiltration, and obfuscation before an agent consumes it. Returns a verdict (clean|suspicious|attack), probability, bits-at-risk (upper bound on adversarial capture per the Adversarial Landauer bound), matched canon patterns, and a recommended action (allow|sanitize|reject|escalate). Backed by Aristotle-verified theorems T-IB-02/T-IB-06/T-IB-01.

入力スキーマ

{
  "type": "object",
  "properties": {
    "input": {
      "type": "string",
      "description": "The untrusted text/data to screen.",
      "minLength": 1,
      "maxLength": 200000
    },
    "context": {
      "type": "string",
      "description": "Optional: the agent's role/system prompt; helps calibrate."
    },
    "certainty": {
      "type": "string",
      "enum": [
        "quick",
        "standard",
        "premium"
      ],
      "description": "Operating point. Default standard."
    },
    "agentId": {
      "type": "string",
      "description": "Optional: for MCP-01 envelope cross-check."
    }
  },
  "required": [
    "input"
  ],
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "properties": {
    "verdict": {
      "type": "string",
      "enum": [
        "clean",
        "suspicious",
        "attack"
      ]
    },
    "probability": {
      "type": "number"
    },
    "bitsAtRisk": {
      "type": "number"
    },
    "operatingPoint": {
      "type": "object"
    },
    "matchedPatterns": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "recommendedAction": {
      "type": "string",
      "enum": [
        "allow",
        "sanitize",
        "reject",
        "escalate"
      ]
    },
    "signals": {
      "type": "object"
    },
    "explainabilityToken": {
      "type": "string"
    },
    "backedBy": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  },
  "required": [
    "verdict",
    "probability",
    "bitsAtRisk",
    "recommendedAction"
  ]
}
🟢detect_trace_tool_policy(trace, traces, targetName)

Analyze an agent trace for the Gray Swan Wave 16 class: untrusted retrieved/tool output causing a tool call outside the user-declared per-turn allowlist. Returns trace counts, unauthorized tool-call evidence, canon mapping VC-AI-TOOL-0001, and claim-boundary guardrails. Backed by T-IB-25/T-IB-29/T-IB-36.

入力スキーマ

{
  "type": "object",
  "properties": {
    "trace": {
      "type": "object",
      "description": "Single agent trace with user_prompt, allowed_tools, and events[].",
      "additionalProperties": true
    },
    "traces": {
      "type": "array",
      "description": "Optional batch of agent traces.",
      "items": {
        "type": "object",
        "additionalProperties": true
      }
    },
    "targetName": {
      "type": "string",
      "description": "Optional display name for the assessed target."
    }
  },
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "properties": {
    "mode": {
      "type": "string",
      "enum": [
        "trace_tool_policy_probe"
      ]
    },
    "verdict": {
      "type": "string",
      "enum": [
        "clean",
        "suspicious",
        "attack"
      ]
    },
    "probability": {
      "type": "number"
    },
    "recommendedAction": {
      "type": "string",
      "enum": [
        "allow",
        "sanitize",
        "reject",
        "escalate"
      ]
    },
    "canonId": {
      "type": "string"
    },
    "theoremRefs": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "customerSystemProved": {
      "type": "boolean"
    },
    "claimBoundary": {
      "type": "string"
    },
    "summary": {
      "type": "object"
    },
    "traces": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "reviewPriority": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "explainabilityToken": {
      "type": "string"
    }
  },
  "required": [
    "mode",
    "verdict",
    "recommendedAction",
    "summary",
    "reviewPriority"
  ]
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 2 件
検証済みバージョンは記録されていませんツール 2 件