Security scanner for MCP servers and AI skills. Detects invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names. Trust scoring for the agent economy — scan before you trust.
Registry: io.github.entradox/trust-scan ·
Remote: https://trust-scan-production.up.railway.app/mcp/
{
"mcpServers": {
"trust-scan": {
"url": "https://trust-scan-production.up.railway.app/mcp/"
}
}
}
Exposes two tools: trust_scan_server (directory or file, with typosquat check) and trust_scan_file (single file).
curl -X POST https://trust-scan-production.up.railway.app/v1/scan \
-H "Content-Type: application/json" \
-d '{"path": "/path/to/mcp-server"}'
curl https://trust-scan-production.up.railway.app/health