Mmcp.market

TrustScan MCP server

by entradox·io.github.entradox/trust-scan·v0.1.0

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

C67/100grade C
What users say
No reviews yet
Be the first
Safety scan
C67/100

full report

Adoption
New

Little public usage data yet

Reviews

Write one

Nobody has reviewed TrustScan yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

TrustScan tools (4)

write = sends, deletes, buys or posts
  • read_skillFree

    Read a product skill file by its skill:// URI.

  • skills_list_toolFree

    List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.

  • trust_scan_fileFree

    Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.

  • trust_scan_serverFree

    Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

no findings
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 540ms20/20
  • Tool poisoning4 tool descriptions checked15/15
  • Auth qualityopen endpoint, read-only tools10/15
  • Maintenancerepository not readable: repo not found3/15
  • Maintainer identityno repository or website to verify2/10
Overall 67/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http trust-scan https://trust-scan-production.up.railway.app/mcp/
Add to Cursor

TrustScan: common questions

Is TrustScan MCP server safe?
With care: it is graded C, so read the findings first (67/100). Read the TrustScan safety report
How do I install TrustScan?
It runs remotely at trust-scan-production.up.railway.app. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does TrustScan need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is TrustScan maintained?
The latest release is v0.1.0.
Is TrustScan up?
100% of our last 2 checks got an answer. We check remote servers about four times a day.
What can I use instead of TrustScan?
Servers from other publishers that do the same job: MCP Security & Vulnerability Auditor MCP server, ScanLabsAI Security Scanner MCP server and CodeInspectus MCP server. Compare all TrustScan alternatives.

Alternatives to TrustScan

Same job from other publishers: the closest match first, then the best rated.

All TrustScan alternatives →
  • MCP Security & Vulnerability Auditor
    Static AST security scanner detecting command injection, leaked secrets, and SSRF in MCP tools.
    B
  • ScanLabsAI Security Scanner
    Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
    B
  • CodeInspectus
    Local-first MCP security scanner and CLI for AI-generated applications.
    C
  • grim-mcp
    Security audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.
    C
  • Draugr
    Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
    A

More from entradox