# mcptrustchecker

> mcptrustchecker — illia-haidar-mcptrustchecker. Use this tool when you need to scan Model Context Protocol (MCP) servers for security vulnerabilities and detect potential threats such as toxic flows, Unicode smuggling, and prompt injections. It provides a deterministic and auditable Trust Score from 0-100, allowing for informed decision-making. Ideal for use cases where security and trust are paramount, such as in git-based development environments.

Canonical page: https://skillsregistry.net/skills/illia-haidar-mcptrustchecker  
JSON: https://api.skillsregistry.net/v1/skills/illia-haidar-mcptrustchecker

## Description

Local-first, deterministic security scanner for Model Context Protocol (MCP) servers. Cross-tool toxic-flow analysis, Unicode-smuggling decode, prompt-injection & supply-chain detection, with an auditable 0–100 Trust Score.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **License:** MIT
- **Updated:** 2026-09-22

## Source

- **Source listing:** [GitHub](https://github.com/illia-haidar/mcptrustchecker)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "illia-haidar-mcptrustchecker"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/illia-haidar-mcptrustchecker` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/illia-haidar-mcptrustchecker/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
