AIShield Security Scanner
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
我该使用它吗
质量与安全性
发现(4)
- LOW在 aishield_scan 中
- LOW在 aishield_prompt_check 中
- LOW在 aishield_banned_words 中
- LOW在 aishield_vertical_risk 中
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"aishield": {
"command": "npx",
"args": [
"aishield-mcp-server"
]
}
}
}可运行的软件包
4.3.0stdio远程端点
https://aishield.tools/api/v1/mcpstreamable-http它能做什么
工具清单
工具(10)
⚪aishield_scan(source_url, tool_type, name)
OWASP MCP Top 10 aligned security scan — 235 rules, 5-dimension scoring
输入模式
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
},
"tool_type": {
"type": "string",
"enum": [
"mcp",
"skill",
"gpt",
"prompt"
],
"default": "mcp"
},
"name": {
"type": "string",
"description": "Tool name"
}
},
"required": [
"source_url"
]
}🟢aishield_guardrail(source_url, auto_block)
Pre-install safety check — pass/block verdict
输入模式
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
},
"auto_block": {
"type": "boolean",
"default": true
}
},
"required": [
"source_url"
]
}🟢aishield_prompt_check(prompt)
Prompt injection detection — Chinese + English
输入模式
{
"type": "object",
"properties": {
"prompt": {
"type": "string",
"description": "Prompt text to check (min 10 chars)"
}
},
"required": [
"prompt"
]
}⚪aishield_banned_words(text, platform)
Chinese banned words detection — 6 platform rules
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string",
"description": "Text to check"
},
"platform": {
"type": "string",
"enum": [
"douyin",
"xiaohongshu",
"wechat",
"weibo",
"bilibili",
"kuaishou",
"all"
],
"default": "all"
}
},
"required": [
"text"
]
}🟢aishield_rug_pull(source_url)
Rug pull detection — check if a tool has removed security code or added suspicious changes in recent commits
输入模式
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
}
},
"required": [
"source_url"
]
}🟢aishield_handshake(source_url)
MCP handshake verification — analyze MCP config, detect npx auto-install, sensitive env vars, oversized tool descriptions, and attempt HTTP handshake
输入模式
{
"type": "object",
"properties": {
"source_url": {
"type": "string",
"description": "GitHub repo URL"
}
},
"required": [
"source_url"
]
}⚪aishield_digest(configs, scan_result, source_url, max_findings)
Compact trust digest (aishield-digest/v1) — a few hundred bytes plus a content fingerprint, so an agent can answer 'can I trust this?' every turn without re-pulling the full report. Accepts {configs} (static analysis only), {scan_result}, or {source_url}. The returned `risk` is never lighter than the worst finding actually present (a config with high findings is never labelled 'safe'), and no plaintext credential is ever echoed back.
输入模式
{
"type": "object",
"properties": {
"configs": {
"type": "object",
"description": "{path: file content} MCP client config map — static analysis, no command in the config is ever executed"
},
"scan_result": {
"type": "object",
"description": "An existing scan result to compress"
},
"source_url": {
"type": "string",
"description": "GitHub repo URL — return the current trust verdict as a digest"
},
"max_findings": {
"type": "integer",
"minimum": 0,
"maximum": 20,
"default": 3,
"description": "How many top findings to include"
}
}
}⚪aishield_vertical_risk(text, domain)
Vertical-industry risk scan — detect high-risk claims for finance/medical/gov sectors (unlicensed diagnosis, illegal medical device, financial over-promise, etc.)
输入模式
{
"type": "object",
"properties": {
"text": {
"type": "string",
"description": "Text content to scan"
},
"domain": {
"type": "string",
"enum": [
"finance",
"medical",
"government"
],
"default": "finance",
"description": "Vertical domain"
}
},
"required": [
"text"
]
}🟢agent_register(agent_name, capabilities, owner)
Agent-First one-click onboarding — register as an Agent, get DID + API Key + quick start guide in a single call
输入模式
{
"type": "object",
"properties": {
"agent_name": {
"type": "string",
"description": "Agent name (required)"
},
"capabilities": {
"type": "array",
"items": {
"type": "string"
},
"description": "Capability list, e.g. [\"scan\", \"monitor\"]"
},
"owner": {
"type": "string",
"description": "Owner identifier"
}
},
"required": [
"agent_name"
]
}⚪agent_quick_scan(tool_name, tool_description, source_url)
Agent-First quick scan — scan a tool by name and description, no source URL required
输入模式
{
"type": "object",
"properties": {
"tool_name": {
"type": "string",
"description": "Tool name (required)"
},
"tool_description": {
"type": "string",
"description": "Tool description (required)"
},
"source_url": {
"type": "string",
"description": "Optional GitHub repo URL for deep scan"
}
},
"required": [
"tool_name",
"tool_description"
]
}社区
证据