TrustScan MCP server
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Little public usage data yet
Reviews
Write oneNobody has reviewed TrustScan yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
TrustScan tools (4)
write = sends, deletes, buys or postsread_skillFreeRead a product skill file by its skill:// URI.
skills_list_toolFreeList this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
trust_scan_fileFreeSecurity-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
trust_scan_serverFreeSecurity-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 540ms20/20
- Tool poisoning4 tool descriptions checked15/15
- Auth qualityopen endpoint, read-only tools10/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Install directly
claude mcp add --transport http trust-scan https://trust-scan-production.up.railway.app/mcp/
TrustScan: common questions
- Is TrustScan MCP server safe?
- With care: it is graded C, so read the findings first (67/100). Read the TrustScan safety report
- How do I install TrustScan?
- It runs remotely at trust-scan-production.up.railway.app. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does TrustScan need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is TrustScan maintained?
- The latest release is v0.1.0.
- Is TrustScan up?
- 100% of our last 2 checks got an answer. We check remote servers about four times a day.
- What can I use instead of TrustScan?
- Servers from other publishers that do the same job: MCP Security & Vulnerability Auditor MCP server, ScanLabsAI Security Scanner MCP server and CodeInspectus MCP server. Compare all TrustScan alternatives.
Alternatives to TrustScan
Same job from other publishers: the closest match first, then the best rated.
MCP Security & Vulnerability AuditorStatic AST security scanner detecting command injection, leaked secrets, and SSRF in MCP tools.not reviewedGrowingB
ScanLabsAI Security ScannerScan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixesnot reviewedNewB- CodeInspectusLocal-first MCP security scanner and CLI for AI-generated applications.not reviewedGrowingC
- grim-mcpSecurity audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.not reviewedGrowingC
DraugrSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.not reviewedGrowingA