mcpbeat Sign in

TrustScan MCP Server

answering

TrustScan is answering right now. Last checked moments ago. It exposes 2 tools.

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

The linked repository no longer exists on GitHub — it was deleted or made private.

Uptime history 63 hours of history
63 hours agonow
100.0%
Uptime 24h
93 of 93 checks
2
Tools
read from the server
354 ms
Response time
average over 24h
open, no key
Access
streamable-http

This one has been quiet for a while

Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 0 min ago.

run in your terminal
claude mcp add trust-scan --transport http https://trust-scan-production.up.railway.app/mcp/
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "trust-scan": {
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}
~/.codex/config.toml
[mcp_servers.trust-scan]
url = "https://trust-scan-production.up.railway.app/mcp/"
.cursor/mcp.json
{
  "mcpServers": {
    "trust-scan": {
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "trust-scan": {
      "url": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}

Available tools 2

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

trust
trust_scan_file
Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detail (rule, severity, location). Read-only: the file is never modified.
trust_scan_server
Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code patterns (MCP001–006), hardcoded secrets, typosquat package names — and returns a 0-100 score, letter grade, and detailed findings. Run this on any directory BEFORE wiring it into your agent. Read-only: never modifies the scanned target.

Endpoints

URLTransportStateLatencyChecked
https://trust-scan-production.up.railway.app/mcp/ streamable-http answering 429 ms 0 min ago

Alternatives to TrustScan

same job, measured the same way
MCP Shield
by sophiacave

Security scanner for MCP servers. SSRF, path traversal, injection, auth, secrets. Grade A-F.

36 installs/wk local only
Mcpshield
by mcpshield-dev

Security scanner for MCP servers - detects tool poisoning and injection

46 installs/wk local only
Mund — MCP Security Scanner
by tyox-all

Scan for prompt injection, secrets, PII, and vet MCP servers before installation

46 installs/wk local only
Hares — MCP security scanner
by alialrikabi313

Multi-layer security scanner for MCP servers and agent skills (injection, exfiltration)

15 installs/wk local only
Aguara MCP
by garagon

Security scanner for AI agent skills and MCP servers

local only
Shadowgate MCP
by josephibra

Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.

answering
I
Mcpsentry
by roshan6335

Security scanner and runtime proxy for MCP servers.

45 installs/wk local only
Vibescan MCP Server
by aguantar

MCP server for VibeScan — scan projects for leaked secrets and security issues

68 installs/wk local only

TrustScan — questions

Answers built from our own checks of this server.

What can TrustScan do?
It exposes 2 tools, read directly from the server on our last check. Among them: trust_scan_file, trust_scan_server. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is TrustScan working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 93 of 93 checks got a reply (100.0%), average response time 354 ms. The bar chart above shows every period we have measured.
Is TrustScan still maintained?
The linked repository no longer exists on GitHub — it was deleted or made private. We show this because it changes what you can expect: an unmaintained server may keep answering for months and then stop without warning.
How do I connect TrustScan?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does TrustScan need an API key?
No. TrustScan completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 2 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is TrustScan?
It answers our handshake in 354 ms on average, which is faster than 47% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.