TrustScan

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
83%
이름 품질
85%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~522토큰 (도구 정의)
~683 B일반적인 응답 크기
최소한의 주의 영향 (128k 컨텍스트의 0.41%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "trust-scan": {
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}

원격 엔드포인트

https://trust-scan-production.up.railway.app/mcp/streamable-http

할 수 있는 일

도구 목록

도구 (4)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟢trust_scan_server(path, package_name)

Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.

입력 스키마

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "directory or file path to scan (on the TrustScan host)"
    },
    "package_name": {
      "default": "",
      "type": "string",
      "description": "package name for typosquat detection (e.g. \"mcp-server\")"
    }
  },
  "required": [
    "path"
  ],
  "additionalProperties": false
}

출력 스키마

{
  "type": "object",
  "additionalProperties": true
}
🟢trust_scan_file(filepath)

Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.

입력 스키마

{
  "type": "object",
  "properties": {
    "filepath": {
      "type": "string",
      "description": "absolute path of the file to scan"
    }
  },
  "required": [
    "filepath"
  ],
  "additionalProperties": false
}

출력 스키마

{
  "type": "object",
  "additionalProperties": true
}
🟢skills_list_tool

List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.

입력 스키마

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

출력 스키마

{
  "type": "object",
  "additionalProperties": true
}
🟢read_skill(uri)

Read a product skill file by its skill:// URI.

입력 스키마

{
  "type": "object",
  "properties": {
    "uri": {
      "type": "string",
      "description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
    }
  },
  "required": [
    "uri"
  ],
  "additionalProperties": false
}

출력 스키마

{
  "type": "object",
  "additionalProperties": true
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 4개
검증됨버전이 기록되지 않음도구 4개