security-preflight
Static MCP, source-code and injection-indicator checks with redacted signed receipts.
我該用這個嗎
品質與安全性
發現項目(1)
- LOW在 describe_agent 中
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"security-preflight": {
"url": "https://mcp.viridisconservation.com/security-preflight/mcp"
}
}
}遠端端點
https://mcp.viridisconservation.com/security-preflight/mcpstreamable-httphttps://mcp.viridis-security.com/security-preflight/mcpstreamable-http它能做什麼
工具清單
工具(5)
⚪security_preflight(agent_id, manifest, subject_profile_sha256, policy, sample_inputs, ...)
Run a $1 static Security Preflight and return a signed receipt. New x402 payer wallets may receive the fleet-wide $0.01 introductory call. No deployed endpoint is fetched or tested. Importing the receipt into an Agent Market profile is a separate, explicit action.
輸入結構描述
{
"type": "object",
"properties": {
"agent_id": {
"title": "Agent Id",
"type": "string"
},
"manifest": {
"additionalProperties": true,
"title": "Manifest",
"type": "object"
},
"subject_profile_sha256": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Subject Profile Sha256"
},
"policy": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"title": "Policy"
},
"sample_inputs": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"title": "Sample Inputs"
},
"payment_ref": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Payment Ref"
},
"request_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Request Id"
}
},
"required": [
"agent_id",
"manifest"
],
"title": "security_preflightArguments"
}輸出結構描述
{
"type": "object",
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "security_preflightOutput"
}⚪scan_source(agent_id, source)
$1 bounded inline VulnCanon source scan; indicators, not proven exploits. At most 64 KiB, 2000 lines, 4096 characters per line. No model calls, repository fetching or code execution. Returns a redacted signed receipt.
輸入結構描述
{
"type": "object",
"properties": {
"agent_id": {
"title": "Agent Id",
"type": "string"
},
"source": {
"title": "Source",
"type": "string"
}
},
"required": [
"agent_id",
"source"
],
"title": "scan_sourceArguments"
}輸出結構描述
{
"type": "object",
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "scan_sourceOutput"
}⚪screen_injection(agent_id, texts)
$1 batch of 1–20 text samples screened for deterministic injection markers. Maximum 64 KiB total. Heuristic indicators, not calibrated probabilities or a guarantee of safety. No model calls or automatic follow-on purchase.
輸入結構描述
{
"type": "object",
"properties": {
"agent_id": {
"title": "Agent Id",
"type": "string"
},
"texts": {
"items": {
"type": "string"
},
"title": "Texts",
"type": "array"
}
},
"required": [
"agent_id",
"texts"
],
"title": "screen_injectionArguments"
}輸出結構描述
{
"type": "object",
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "screen_injectionOutput"
}🟢get_security_receipt(receipt_id)
Read a previously issued public, input-redacted receipt.
輸入結構描述
{
"type": "object",
"properties": {
"receipt_id": {
"title": "Receipt Id",
"type": "string"
}
},
"required": [
"receipt_id"
],
"title": "get_security_receiptArguments"
}輸出結構描述
{
"type": "object",
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "get_security_receiptOutput"
}🟢describe_agent
Describe scope, evidence boundary, inputs, and outputs.
輸入結構描述
{
"type": "object",
"properties": {},
"title": "describe_agentArguments"
}輸出結構描述
{
"type": "object",
"properties": {
"result": {
"title": "Result",
"type": "string"
}
},
"required": [
"result"
],
"title": "describe_agentOutput"
}社群
證據