Serveur MCP

TrustScan

io.github.entradox/trust-scan
Sécurité Public et accessible MCP 2025-11-25

Ce que fait ce MCP

Scans MCP servers, skills, and files for prompt-injection Unicode, dangerous code patterns, secrets, and typosquatting.

read_skill
Read Skill
Read a product skill file by its skill:// URI.
Schéma d’entrée
{'type': 'object', 'required': ['uri'], 'properties': {'uri': {'type': 'string', 'description': 'e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`.'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
skills_list_tool
Skills List Tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
Schéma d’entrée
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
trust_scan_file
Scan Single File
Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['filepath'], 'properties': {'filepath': {'type': 'string', 'description': 'absolute path of the file to scan'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
trust_scan_server
Scan MCP Server or Skill Package
Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['path'], 'properties': {'path': {'type': 'string', 'description': 'directory or file path to scan (on the TrustScan host)'}, 'package_name': {'type': 'string', 'default': '', 'description': 'package name for typosquat detection (e.g. "mcp-server")'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'additionalProperties': True}
Ajouté
read_skill
17 September 2026 12:41
Ajouté
skills_list_tool
17 September 2026 12:41
Ajouté
trust_scan_file
17 September 2026 12:41
Ajouté
trust_scan_server
17 September 2026 12:41