injection-detector
Formally-verified injection/exfiltration detector for AI agents (MCP-02).
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"injection-detector": {
"url": "https://mcp.viridis-security.com/mcp"
}
}
}遠端端點
https://mcp.viridis-security.com/mcpstreamable-http它能做什麼
工具清單
工具(2)
⚪detect_injection(input, context, certainty, agentId)
Screen untrusted input for prompt/tool injection, exfiltration, and obfuscation before an agent consumes it. Returns a verdict (clean|suspicious|attack), probability, bits-at-risk (upper bound on adversarial capture per the Adversarial Landauer bound), matched canon patterns, and a recommended action (allow|sanitize|reject|escalate). Backed by Aristotle-verified theorems T-IB-02/T-IB-06/T-IB-01.
輸入結構描述
{
"type": "object",
"properties": {
"input": {
"type": "string",
"description": "The untrusted text/data to screen.",
"minLength": 1,
"maxLength": 200000
},
"context": {
"type": "string",
"description": "Optional: the agent's role/system prompt; helps calibrate."
},
"certainty": {
"type": "string",
"enum": [
"quick",
"standard",
"premium"
],
"description": "Operating point. Default standard."
},
"agentId": {
"type": "string",
"description": "Optional: for MCP-01 envelope cross-check."
}
},
"required": [
"input"
],
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"properties": {
"verdict": {
"type": "string",
"enum": [
"clean",
"suspicious",
"attack"
]
},
"probability": {
"type": "number"
},
"bitsAtRisk": {
"type": "number"
},
"operatingPoint": {
"type": "object"
},
"matchedPatterns": {
"type": "array",
"items": {
"type": "string"
}
},
"recommendedAction": {
"type": "string",
"enum": [
"allow",
"sanitize",
"reject",
"escalate"
]
},
"signals": {
"type": "object"
},
"explainabilityToken": {
"type": "string"
},
"backedBy": {
"type": "array",
"items": {
"type": "string"
}
}
},
"required": [
"verdict",
"probability",
"bitsAtRisk",
"recommendedAction"
]
}🟢detect_trace_tool_policy(trace, traces, targetName)
Analyze an agent trace for the Gray Swan Wave 16 class: untrusted retrieved/tool output causing a tool call outside the user-declared per-turn allowlist. Returns trace counts, unauthorized tool-call evidence, canon mapping VC-AI-TOOL-0001, and claim-boundary guardrails. Backed by T-IB-25/T-IB-29/T-IB-36.
輸入結構描述
{
"type": "object",
"properties": {
"trace": {
"type": "object",
"description": "Single agent trace with user_prompt, allowed_tools, and events[].",
"additionalProperties": true
},
"traces": {
"type": "array",
"description": "Optional batch of agent traces.",
"items": {
"type": "object",
"additionalProperties": true
}
},
"targetName": {
"type": "string",
"description": "Optional display name for the assessed target."
}
},
"additionalProperties": false
}輸出結構描述
{
"type": "object",
"properties": {
"mode": {
"type": "string",
"enum": [
"trace_tool_policy_probe"
]
},
"verdict": {
"type": "string",
"enum": [
"clean",
"suspicious",
"attack"
]
},
"probability": {
"type": "number"
},
"recommendedAction": {
"type": "string",
"enum": [
"allow",
"sanitize",
"reject",
"escalate"
]
},
"canonId": {
"type": "string"
},
"theoremRefs": {
"type": "array",
"items": {
"type": "string"
}
},
"customerSystemProved": {
"type": "boolean"
},
"claimBoundary": {
"type": "string"
},
"summary": {
"type": "object"
},
"traces": {
"type": "array",
"items": {
"type": "object"
}
},
"reviewPriority": {
"type": "array",
"items": {
"type": "object"
}
},
"explainabilityToken": {
"type": "string"
}
},
"required": [
"mode",
"verdict",
"recommendedAction",
"summary",
"reviewPriority"
]
}社群
證據