MCP serverio.github.entradox/trust-scan
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Overview
Score?
UNRATED 0.726
of what a free look can see, on 23 looks
Looks
27
last 7 hr ago
Tools
4
changed 19 days ago
More info
URL
trust-scan-production.up.railway.app/mcp/
streamable-http
Says it is
trust-scan 4.0.10
protocol 2025-06-18
In the record since
25 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.726 · highest on record 0.8561
Toolsfrom sha256:a1c5b7d67d…6d2194 · +2 −0 19 days ago
| Tool | Schema |
|---|---|
| read_skill added Read a product skill file by its skill:// URI. |
input · output |
| skills_list_tool added List this product's skills. Each entry carries the SKILL.md URI,
its name and description, verbatim frontmatter, and a per-file
sha256 manifest. Read a body with `read_skill`. |
input · output |
| trust_scan_file Security-scan a single file for invisible Unicode, dangerous patterns, and secrets.
Returns a severity-weighted score and per-finding detail (rule, severity,
location). Read-only: |
input · output |
| trust_scan_server Security-scan an MCP server or skill package before trusting it.
Runs all four checks — invisible Unicode prompt-injection, dangerous code
patterns (MCP001–006), hardcoded secrets |
input · output |
Verify it yourself
npx teppi-check https://trust-scan-production.up.railway.app/mcp/curl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M22BHS0TR0JVPXDMPNZ33N6Z