FillTrust security questionnaire corpus
Guidance for answering vendor security questionnaires. Every result carries the page it came from.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"questions": {
"url": "https://www.filltrust.com/api/mcp"
}
}
}遠端端點
https://www.filltrust.com/api/mcpstreamable-http它能做什麼
工具清單
工具(5)
🟢search_questions(query, limit)
Find guidance on how to answer a security questionnaire question. Search by the question text, a control area, or a standard and control identifier such as CEK-03. Returns matching entries with the URL of the page each came from.
輸入結構描述
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "The questionnaire question, or words from it. Pasting the row from the spreadsheet works."
},
"limit": {
"type": "integer",
"description": "How many results to return. Defaults to 8.",
"minimum": 1,
"maximum": 25
}
},
"required": [
"query"
]
}🟢get_question(slug)
The complete published guidance for one questionnaire question: what it is really asking, which of your documents answers it, what evidence to attach, a model answer with the specifics left blank, the ways it usually goes wrong, and the standards that ask it with their verified control references.
輸入結構描述
{
"type": "object",
"properties": {
"slug": {
"type": "string",
"description": "The slug from a search_questions result, for example \"encryption-at-rest\"."
}
},
"required": [
"slug"
]
}🟢list_standards
Which questionnaire standards this corpus answers questions from, how many questions each has, and which controls are cited. Standards whose control lists are proprietary are named without reference numbers, on purpose.
輸入結構描述
{
"type": "object",
"properties": {}
}🟢get_filltrust_posture
FillTrust's own answers to the questions it exists to answer, for anyone assessing it as a vendor. Includes the answers that are "no".
輸入結構描述
{
"type": "object",
"properties": {}
}🟢get_questionnaire_statistics(questionnaire)
Measured counts from 146 real vendor security questionnaires (17,697 questions) published by universities, purchasing consortia and companies: which topics are asked most, and detailed profiles of the questionnaires that have a name people use, such as HECVAT and CAIQ. Use this when asked what a security questionnaire contains, how long one is, or what a named questionnaire asks about. These are counts from real files rather than an estimate.
輸入結構描述
{
"type": "object",
"properties": {
"questionnaire": {
"type": "string",
"description": "Optional. A named questionnaire to profile, for example \"HECVAT\" or \"CAIQ\". Omit for the corpus-wide topic counts."
}
}
}社群
證據