https://trust-scan-production.up.railway.app/mcp/ ↗
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
TrustScan is a remote MCP server published at trust-scan-production.up.railway.app. It has been probed 6 times since 9/12/2026. It answered in 6 of them (100.0%), a near-uninterrupted record. Median response time is 425 ms, placing it among the faster endpoints. It offers a narrow, focused set of 2 tools. On the protocol side it speaks the 2026-07-28 stateless spec.
Can an LLM agent pick the right tool here — names, descriptions and parameter clarity are assessed.
trust_scan_server — Ambiguous 'BE' abbreviation in descriptiontrust_scan_server — Typosquat check mentioned without clear scopetrust_scan_file — No mention of file size limitations or format requirementsRisk: low
tools/list structure, inputSchema validity, and a functional smoke test — the components of the 0-100 score.
Tools the server advertised in the latest measurement — measured, not catalog-claimed.
trust_scan_serverSecurity-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
pathstringrequiredpackage_namestringtrust_scan_fileSecurity-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
filepathstringrequiredDerived by comparing consecutive probes — changes in era, protocol version, build and reachability.
Add this badge to your README — it updates automatically as measurements change.
[](https://mcpmetrics.io/servers/io-github-entradox-trust-scan)<a href="https://mcpmetrics.io/servers/io-github-entradox-trust-scan"><img src="https://mcpmetrics.io/badge/io.github.entradox/trust-scan/era.svg" alt="mcpmetrics"></a>You are seeing the last 7 days. Sign up for the full history. Which check failed and why is in the dashboard.
Sign up free to seeThe catalog entries whose name and description are closest to this one, found with the same index the search box uses.
AI skill security scanner. Detects prompt injection, credential theft, ClawHavoc. Free, no signup.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
AWS cloud security scanners for AI agents — S3, IAM, EC2, EKS, RDS, CloudTrail, CloudWatch Logs
DNS and email security scanner with 79 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.
| Run | Era | Modern | ms | Legacy | ms | Versions |
|---|---|---|---|---|---|---|
| 2026-09-13 01:33:33 | Dual-era | 200 | 384 | 200 | 381 | 2026-07-28 |
| 2026-09-12 23:31:36 | Dual-era | 200 | 344 | 200 | 343 | 2026-07-28 |
| 2026-09-12 21:29:15 | Dual-era | 200 | 395 | 200 | 391 | 2026-07-28 |
| 2026-09-12 19:27:29 | Dual-era | 200 | 480 | 200 | 496 | 2026-07-28 |
| 2026-09-12 17:24:09 | Dual-era | 200 | 476 | 200 | 475 | 2026-07-28 |
| 2026-09-12 15:21:42 | Dual-era | 200 | 425 | 200 | 426 | 2026-07-28 |
Each block is one measurement round. Green: working response. Amber: responded but the server was returning errors (5xx). Red: no response at all.
Each cell is one probe run. Faded cells are incomplete probes — one leg did not answer, so the era is inconclusive.
The two probe legs separately: modern server/discover and legacy initialize.
Comments
Sign in to write a comment
No comments yet. Be the first.