AIShield Security Scanner

Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

사용해야 할까요

품질 및 안전성

A
설명 품질
82%
스키마 완전성
96%
이름 품질
80%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

발견 사항 (4)

  • LOWTool 'aishield_scan' description lacks action verbaishield_scan에서
  • LOWTool 'aishield_prompt_check' description lacks action verbaishield_prompt_check에서
  • LOWTool 'aishield_banned_words' description lacks action verbaishield_banned_words에서
  • LOWTool 'aishield_vertical_risk' description lacks action verbaishield_vertical_risk에서

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~984토큰 (도구 정의)
~712 B일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 0.77%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "aishield": {
      "command": "npx",
      "args": [
        "aishield-mcp-server"
      ]
    }
  }
}

실행 가능한 패키지

npmaishield-mcp-server4.3.0stdio

원격 엔드포인트

https://aishield.tools/api/v1/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (10)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
⚪aishield_scan(source_url, tool_type, name)

OWASP MCP Top 10 aligned security scan — 235 rules, 5-dimension scoring

입력 스키마

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    },
    "tool_type": {
      "type": "string",
      "enum": [
        "mcp",
        "skill",
        "gpt",
        "prompt"
      ],
      "default": "mcp"
    },
    "name": {
      "type": "string",
      "description": "Tool name"
    }
  },
  "required": [
    "source_url"
  ]
}
🟢aishield_guardrail(source_url, auto_block)

Pre-install safety check — pass/block verdict

입력 스키마

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    },
    "auto_block": {
      "type": "boolean",
      "default": true
    }
  },
  "required": [
    "source_url"
  ]
}
🟢aishield_prompt_check(prompt)

Prompt injection detection — Chinese + English

입력 스키마

{
  "type": "object",
  "properties": {
    "prompt": {
      "type": "string",
      "description": "Prompt text to check (min 10 chars)"
    }
  },
  "required": [
    "prompt"
  ]
}
⚪aishield_banned_words(text, platform)

Chinese banned words detection — 6 platform rules

입력 스키마

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "description": "Text to check"
    },
    "platform": {
      "type": "string",
      "enum": [
        "douyin",
        "xiaohongshu",
        "wechat",
        "weibo",
        "bilibili",
        "kuaishou",
        "all"
      ],
      "default": "all"
    }
  },
  "required": [
    "text"
  ]
}
🟢aishield_rug_pull(source_url)

Rug pull detection — check if a tool has removed security code or added suspicious changes in recent commits

입력 스키마

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    }
  },
  "required": [
    "source_url"
  ]
}
🟢aishield_handshake(source_url)

MCP handshake verification — analyze MCP config, detect npx auto-install, sensitive env vars, oversized tool descriptions, and attempt HTTP handshake

입력 스키마

{
  "type": "object",
  "properties": {
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL"
    }
  },
  "required": [
    "source_url"
  ]
}
⚪aishield_digest(configs, scan_result, source_url, max_findings)

Compact trust digest (aishield-digest/v1) — a few hundred bytes plus a content fingerprint, so an agent can answer 'can I trust this?' every turn without re-pulling the full report. Accepts {configs} (static analysis only), {scan_result}, or {source_url}. The returned `risk` is never lighter than the worst finding actually present (a config with high findings is never labelled 'safe'), and no plaintext credential is ever echoed back.

입력 스키마

{
  "type": "object",
  "properties": {
    "configs": {
      "type": "object",
      "description": "{path: file content} MCP client config map — static analysis, no command in the config is ever executed"
    },
    "scan_result": {
      "type": "object",
      "description": "An existing scan result to compress"
    },
    "source_url": {
      "type": "string",
      "description": "GitHub repo URL — return the current trust verdict as a digest"
    },
    "max_findings": {
      "type": "integer",
      "minimum": 0,
      "maximum": 20,
      "default": 3,
      "description": "How many top findings to include"
    }
  }
}
⚪aishield_vertical_risk(text, domain)

Vertical-industry risk scan — detect high-risk claims for finance/medical/gov sectors (unlicensed diagnosis, illegal medical device, financial over-promise, etc.)

입력 스키마

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "description": "Text content to scan"
    },
    "domain": {
      "type": "string",
      "enum": [
        "finance",
        "medical",
        "government"
      ],
      "default": "finance",
      "description": "Vertical domain"
    }
  },
  "required": [
    "text"
  ]
}
🟢agent_register(agent_name, capabilities, owner)

Agent-First one-click onboarding — register as an Agent, get DID + API Key + quick start guide in a single call

입력 스키마

{
  "type": "object",
  "properties": {
    "agent_name": {
      "type": "string",
      "description": "Agent name (required)"
    },
    "capabilities": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Capability list, e.g. [\"scan\", \"monitor\"]"
    },
    "owner": {
      "type": "string",
      "description": "Owner identifier"
    }
  },
  "required": [
    "agent_name"
  ]
}
⚪agent_quick_scan(tool_name, tool_description, source_url)

Agent-First quick scan — scan a tool by name and description, no source URL required

입력 스키마

{
  "type": "object",
  "properties": {
    "tool_name": {
      "type": "string",
      "description": "Tool name (required)"
    },
    "tool_description": {
      "type": "string",
      "description": "Tool description (required)"
    },
    "source_url": {
      "type": "string",
      "description": "Optional GitHub repo URL for deep scan"
    }
  },
  "required": [
    "tool_name",
    "tool_description"
  ]
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 10개
검증됨버전이 기록되지 않음도구 9개