Dredd MCP
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"dredd-mcp": {
"url": "https://analytics.dugganusa.com/api/v1/dredd/mcp"
}
}
}遠端端點
https://analytics.dugganusa.com/api/v1/dredd/mcpstreamable-http它能做什麼
工具清單
工具(1)
🟢check_mcp_server(server, version, tool)
Pre-flight security verdict for an MCP server invocation. Judges BOTH server-level reputation AND the server's dependency graph (npm/pypi) against the DugganUSA threat-intel corpus (1.13M+ IOCs, Shai-Hulud + typosquat + LOLBin families). Returns BLOCK / ADVISORY / REVIEW / ALLOW with severity, evidence, dep-graph summary, and HMAC-signed response. REVIEW means we hold NO RECORD of this server -- not that it is safe. Treat REVIEW as do-not-proceed-blindly: a brand-new attacker-published server looks exactly like this. ALLOW is only returned when we actually resolved the server and scanned its dependency graph; check known_to_us and dep_graph.scanned to confirm. Use this BEFORE invoking any other MCP server tool, especially ones installed from outside the official MCP Registry.
輸入結構描述
{
"type": "object",
"properties": {
"server": {
"type": "string",
"description": "MCP server name (e.g. io.github.foo/bar) or substring"
},
"version": {
"type": "string",
"description": "Optional version of the MCP server (semver)"
},
"tool": {
"type": "string",
"description": "Optional name of the specific tool being invoked"
}
},
"required": [
"server"
],
"additionalProperties": false
}社群
證據