Scan MCP Server or Skill Package
trust_scan_serverSecurity-scan an MCP server or skill package before trusting it.
Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | directory or file path to scan (on the TrustScan host) | |
| package_name | No | package name for typosquat detection (e.g. "mcp-server") |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||