FillTrust security questionnaire corpus

Guidance for answering vendor security questionnaires. Every result carries the page it came from.

我该使用它吗

质量与安全性

A
描述质量
92%
模式完整度
70%
命名质量
100%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~515token 数(工具定义)
~440 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.40%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "questions": {
      "url": "https://www.filltrust.com/api/mcp"
    }
  }
}

远程端点

https://www.filltrust.com/api/mcpstreamable-http

它能做什么

工具清单

工具(5)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢search_questions(query, limit)

Find guidance on how to answer a security questionnaire question. Search by the question text, a control area, or a standard and control identifier such as CEK-03. Returns matching entries with the URL of the page each came from.

输入模式

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "The questionnaire question, or words from it. Pasting the row from the spreadsheet works."
    },
    "limit": {
      "type": "integer",
      "description": "How many results to return. Defaults to 8.",
      "minimum": 1,
      "maximum": 25
    }
  },
  "required": [
    "query"
  ]
}
🟢get_question(slug)

The complete published guidance for one questionnaire question: what it is really asking, which of your documents answers it, what evidence to attach, a model answer with the specifics left blank, the ways it usually goes wrong, and the standards that ask it with their verified control references.

输入模式

{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string",
      "description": "The slug from a search_questions result, for example \"encryption-at-rest\"."
    }
  },
  "required": [
    "slug"
  ]
}
🟢list_standards

Which questionnaire standards this corpus answers questions from, how many questions each has, and which controls are cited. Standards whose control lists are proprietary are named without reference numbers, on purpose.

输入模式

{
  "type": "object",
  "properties": {}
}
🟢get_filltrust_posture

FillTrust's own answers to the questions it exists to answer, for anyone assessing it as a vendor. Includes the answers that are "no".

输入模式

{
  "type": "object",
  "properties": {}
}
🟢get_questionnaire_statistics(questionnaire)

Measured counts from 146 real vendor security questionnaires (17,697 questions) published by universities, purchasing consortia and companies: which topics are asked most, and detailed profiles of the questionnaires that have a name people use, such as HECVAT and CAIQ. Use this when asked what a security questionnaire contains, how long one is, or what a named questionnaire asks about. These are counts from real files rather than an estimate.

输入模式

{
  "type": "object",
  "properties": {
    "questionnaire": {
      "type": "string",
      "description": "Optional. A named questionnaire to profile, for example \"HECVAT\" or \"CAIQ\". Omit for the corpus-wide topic counts."
    }
  }
}

社区

评价此服务器

证据

最近观测

已验证未记录版本5 个工具
已验证未记录版本5 个工具