85trust / 100

TrustScan

by trust-scan-production.up.railway.app in Security & trust

MCP serverPassing, checked 2 h ago

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

https://trust-scan-production.up.railway.app/mcp/

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
377 ms typical, 377 ms slowest 5%
Last check
2 h ago
Next check
in 5 h

How to call it

Add it to any MCP client that supports remote servers.

{
  "mcpServers": {
    "trustscan": {
      "type": "http",
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}

4 tools

  • trust_scan_server

    Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this

  • trust_scan_file

    Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.

  • skills_list_tool

    List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.

  • read_skill

    Read a product skill file by its skill:// URI.

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTime
2 h agoPassed200377 ms