TrustScan
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"trust-scan": {
"url": "https://trust-scan-production.up.railway.app/mcp/"
}
}
}원격 엔드포인트
https://trust-scan-production.up.railway.app/mcp/streamable-http할 수 있는 일
도구 목록
도구 (4)
🟢trust_scan_server(path, package_name)
Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
입력 스키마
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "directory or file path to scan (on the TrustScan host)"
},
"package_name": {
"default": "",
"type": "string",
"description": "package name for typosquat detection (e.g. \"mcp-server\")"
}
},
"required": [
"path"
],
"additionalProperties": false
}출력 스키마
{
"type": "object",
"additionalProperties": true
}🟢trust_scan_file(filepath)
Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
입력 스키마
{
"type": "object",
"properties": {
"filepath": {
"type": "string",
"description": "absolute path of the file to scan"
}
},
"required": [
"filepath"
],
"additionalProperties": false
}출력 스키마
{
"type": "object",
"additionalProperties": true
}🟢skills_list_tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
입력 스키마
{
"type": "object",
"properties": {},
"additionalProperties": false
}출력 스키마
{
"type": "object",
"additionalProperties": true
}🟢read_skill(uri)
Read a product skill file by its skill:// URI.
입력 스키마
{
"type": "object",
"properties": {
"uri": {
"type": "string",
"description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
}
},
"required": [
"uri"
],
"additionalProperties": false
}출력 스키마
{
"type": "object",
"additionalProperties": true
}커뮤니티
증거