このMCPでできること
Provides prompt-injection payloads, OWASP LLM risk mappings, AI test packs, and release-planning artifacts for chatbot and agent testing.
ツール
入力スキーマ
{'type': 'object', 'required': ['tests'], 'properties': {'tests': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'prompt', 'check', 'value'], 'properties': {'name': {'type': 'string', 'maxLength': 80, 'description': 'Nonempty ASCII name starting with a letter or number; then letters, numbers, spaces, . _ -. Unique ignoring case.'}, 'check': {'enum': ['contains', 'not_contains', 'equals'], 'type': 'string', 'description': 'How the response is compared with value (case-insensitive).'}, 'value': {'type': 'string', 'maxLength': 1000, 'description': 'Nonblank expected or forbidden text; comparisons ignore case and surrounding whitespace.'}, 'prompt': {'type': 'string', 'maxLength': 4000, 'description': "Nonblank message for the user's chatbot; this tool does not send it."}}, 'additionalProperties': False}, 'maxItems': 20, 'minItems': 1, 'description': '1-20 response tests with unique names.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', 'required': ['category'], 'properties': {'category': {'enum': ['direct', 'encoded', 'indirect', 'multiturn', 'persona', 'retrieval'], 'type': 'string', 'description': 'Required lowercase attack category, e.g. direct for direct instruction overrides or retrieval for retrieved-context attacks; choose one enum value.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', 'required': ['category'], 'properties': {'category': {'enum': ['llm01', 'llm02', 'llm03', 'llm08', 'llm10'], 'type': 'string', 'description': 'Required lowercase risk ID from the enum, llm01 through llm10 (e.g. llm01 for prompt injection); supply the ID, not a category title.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', 'required': ['agent_name', 'release_owner', 'candidate_id', 'system_type', 'authority_boundary', 'human_approval', 'test_scope', 'warning_policy', 'evidence_record', 'rollback', 'rollout', 'feedback_signal'], 'properties': {'rollout': {'enum': ['Progressive or canary rollout', 'Feature flag with rapid disable', 'Full deployment without progressive controls'], 'type': 'string', 'description': 'How the release is deployed.'}, 'blockers': {'type': 'array', 'items': {'enum': ['Confirmed sensitive-data or cross-user disclosure', 'Unauthorized tool or API behavior', 'Hidden instruction or context exposure', 'Unsafe transaction, duplicate action, or false success', 'Prompt injection changes protected behavior', 'Critical validation is incomplete or inconclusive'], 'type': 'string'}, 'maxItems': 6, 'description': 'Observed behaviors that must block release; choose at least three.', 'uniqueItems': True}, 'rollback': {'enum': ['Documented and tested', 'Documented but not tested', 'Not defined'], 'type': 'string', 'description': 'State of the rollback or emergency kill-switch procedure.'}, 'agent_name': {'type': 'string', 'maxLength': 100, 'description': 'Name of the AI system.'}, 'test_scope': {'enum': ['Full release validation', 'Targeted checks followed by full validation', 'No behavioral validation selected'], 'type': 'string', 'description': 'Planned behavioral validation before release.'}, 'system_type': {'enum': ['AI agent', 'Tool-calling workflow', 'RAG system', 'AI chatbot', 'Copilot', 'LLM API'], 'type': 'string', 'description': 'Kind of AI system being released.'}, 'candidate_id': {'type': 'string', 'maxLength': 100, 'description': 'Release candidate, e.g. version or commit SHA.'}, 'capabilities': {'type': 'array', 'items': {'enum': ['Retrieves external or enterprise data', 'Uses persistent or cross-session memory', 'Calls tools or external APIs', 'Creates, changes, sends, or deletes records', 'Handles personal, confidential, regulated, or tenant data', 'Coordinates with other agents'], 'type': 'string'}, 'maxItems': 6, 'description': 'Capabilities of the release candidate; choose all that apply.', 'uniqueItems': True}, 'min_executed': {'type': 'integer', 'maximum': 1000, 'minimum': 1, 'description': 'Default 18.'}, 'data_boundary': {'type': 'string', 'maxLength': 300, 'description': 'Optional sensitive-data and tenant boundary.'}, 'release_owner': {'type': 'string', 'maxLength': 100, 'description': 'Person or role accountable for the release decision.'}, 'human_approval': {'enum': ['Required and implemented', 'Required but not implemented', 'Not required for this read-only release'], 'type': 'string', 'description': 'Whether high-impact actions require human approval and if it is implemented.'}, 'warning_policy': {'enum': ['Human review required', 'Allow without review'], 'type': 'string', 'description': 'How validation warnings are treated in the release gate.'}, 'evidence_record': {'type': 'string', 'maxLength': 300, 'description': 'Where release evidence is kept.'}, 'feedback_signal': {'type': 'string', 'maxLength': 500, 'description': 'Production signal that becomes the next regression test.'}, 'authority_boundary': {'type': 'string', 'maxLength': 800, 'description': 'What the system may do, must never do, and which resources it may access.'}}, 'additionalProperties': False}
最近のツール変更
類似のMCPサーバー
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…