Servidor MCP

injection-detector

io.github.viridis-security/injection-detector
Seguridad Público y accesible MCP 2026-07-28

Qué hace este MCP

Detects prompt injection, data-exfiltration attempts, obfuscation, and unauthorized tool calls in agent traces.

detect_injection
Detect adversarial injection
Screen untrusted input for prompt/tool injection, exfiltration, and obfuscation before an agent consumes it. Returns a verdict (clean|suspicious|attack), probability, bits-at-risk (upper bound on adversarial capture per the Adversarial Landauer bound), matched canon patterns, and a recommended action (allow|sanitize|reject|escalate). Backed by Aristotle-verified theorems T-IB-02/T-IB-06/T-IB-01.
Esquema de entrada
{'type': 'object', 'required': ['input'], 'properties': {'input': {'type': 'string', 'maxLength': 200000, 'minLength': 1, 'description': 'The untrusted text/data to screen.'}, 'agentId': {'type': 'string', 'description': 'Optional: for MCP-01 envelope cross-check.'}, 'context': {'type': 'string', 'description': "Optional: the agent's role/system prompt; helps calibrate."}, 'certainty': {'enum': ['quick', 'standard', 'premium'], 'type': 'string', 'description': 'Operating point. Default standard.'}}, 'additionalProperties': False}
Esquema de salida
{'type': 'object', 'required': ['verdict', 'probability', 'bitsAtRisk', 'recommendedAction'], 'properties': {'signals': {'type': 'object'}, 'verdict': {'enum': ['clean', 'suspicious', 'attack'], 'type': 'string'}, 'backedBy': {'type': 'array', 'items': {'type': 'string'}}, 'bitsAtRisk': {'type': 'number'}, 'probability': {'type': 'number'}, 'operatingPoint': {'type': 'object'}, 'matchedPatterns': {'type': 'array', 'items': {'type': 'string'}}, 'recommendedAction': {'enum': ['allow', 'sanitize', 'reject', 'escalate'], 'type': 'string'}, 'explainabilityToken': {'type': 'string'}}}
detect_trace_tool_policy
Detect trace tool-policy violations
Analyze an agent trace for the Gray Swan Wave 16 class: untrusted retrieved/tool output causing a tool call outside the user-declared per-turn allowlist. Returns trace counts, unauthorized tool-call evidence, canon mapping VC-AI-TOOL-0001, and claim-boundary guardrails. Backed by T-IB-25/T-IB-29/T-IB-36.
Esquema de entrada
{'type': 'object', 'properties': {'trace': {'type': 'object', 'description': 'Single agent trace with user_prompt, allowed_tools, and events[].', 'additionalProperties': True}, 'traces': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'description': 'Optional batch of agent traces.'}, 'targetName': {'type': 'string', 'description': 'Optional display name for the assessed target.'}}, 'additionalProperties': False}
Esquema de salida
{'type': 'object', 'required': ['mode', 'verdict', 'recommendedAction', 'summary', 'reviewPriority'], 'properties': {'mode': {'enum': ['trace_tool_policy_probe'], 'type': 'string'}, 'traces': {'type': 'array', 'items': {'type': 'object'}}, 'canonId': {'type': 'string'}, 'summary': {'type': 'object'}, 'verdict': {'enum': ['clean', 'suspicious', 'attack'], 'type': 'string'}, 'probability': {'type': 'number'}, 'theoremRefs': {'type': 'array', 'items': {'type': 'string'}}, 'claimBoundary': {'type': 'string'}, 'reviewPriority': {'type': 'array', 'items': {'type': 'object'}}, 'recommendedAction': {'enum': ['allow', 'sanitize', 'reject', 'escalate'], 'type': 'string'}, 'explainabilityToken': {'type': 'string'}, 'customerSystemProved': {'type': 'boolean'}}}
Añadido
detect_trace_tool_policy
17 de September de 2026 a las 12:53
Añadido
detect_injection
17 de September de 2026 a las 12:53