TrustScan

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
83%
命名质量
85%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~522token 数(工具定义)
~683 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.41%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "trust-scan": {
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}

远程端点

https://trust-scan-production.up.railway.app/mcp/streamable-http

它能做什么

工具清单

工具(4)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢trust_scan_server(path, package_name)

Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.

输入模式

{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "description": "directory or file path to scan (on the TrustScan host)"
    },
    "package_name": {
      "default": "",
      "type": "string",
      "description": "package name for typosquat detection (e.g. \"mcp-server\")"
    }
  },
  "required": [
    "path"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}
🟢trust_scan_file(filepath)

Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.

输入模式

{
  "type": "object",
  "properties": {
    "filepath": {
      "type": "string",
      "description": "absolute path of the file to scan"
    }
  },
  "required": [
    "filepath"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}
🟢skills_list_tool

List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}
🟢read_skill(uri)

Read a product skill file by its skill:// URI.

输入模式

{
  "type": "object",
  "properties": {
    "uri": {
      "type": "string",
      "description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
    }
  },
  "required": [
    "uri"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}

社区

评价此服务器

证据

最近观测

已验证未记录版本4 个工具
已验证未记录版本4 个工具