TrustScan
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"trust-scan": {
"url": "https://trust-scan-production.up.railway.app/mcp/"
}
}
}遠端端點
https://trust-scan-production.up.railway.app/mcp/streamable-http它能做什麼
工具清單
工具(4)
🟢trust_scan_server(path, package_name)
Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
輸入結構描述
{
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "directory or file path to scan (on the TrustScan host)"
},
"package_name": {
"default": "",
"type": "string",
"description": "package name for typosquat detection (e.g. \"mcp-server\")"
}
},
"required": [
"path"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢trust_scan_file(filepath)
Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
輸入結構描述
{
"type": "object",
"properties": {
"filepath": {
"type": "string",
"description": "absolute path of the file to scan"
}
},
"required": [
"filepath"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢skills_list_tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}🟢read_skill(uri)
Read a product skill file by its skill:// URI.
輸入結構描述
{
"type": "object",
"properties": {
"uri": {
"type": "string",
"description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
}
},
"required": [
"uri"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"additionalProperties": true
}社群
證據