Security scanner for MCP servers and skills: Unicode injection, patterns, secrets. Connect the official TrustScan MCP server to Claude, ChatGPT, or Cursor through gate — one gateway URL, no config files, security-checked.
Free to start · No credit card · No hosting needed
Pick your client. Copy, paste, done — or let gate handle sign-ins and policies for you.
claude mcp add --transport http trustscan https://trust-scan-production.up.railway.app/mcp/Run in your terminal, then restart Claude Code.
TrustScan · https://trust-scan-production.up.railway.app/mcp/
Real prompts you can type the moment it's connected — no setup, no docs to read.
“Use “trust_scan_server”: Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code.”
“Use “trust_scan_file”: Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detai.”
Every server in the gate directory has to pass the same four checks before your AI can touch it. Here's how TrustScan holds up.
gate scanned 2 tools on Sep 9, 2026. A few things are worth a look before you connect.
Operated by TrustScan (github.com) at its documented MCP endpoint — not a third-party mirror or community re-host.
This server only exposes public data — no account and no credentials are involved when you connect.
gate checks every tool for prompt injection, hidden instructions, data-exfiltration hints, and over-broad permissions before the server is available through your gateway.
If TrustScan adds or changes tools later, gate re-scans and alerts you — before your AI acts on the change.
Add one gateway URL to Claude, ChatGPT, or any MCP client. One-time setup, about two minutes.
Choose TrustScan in the gate directory. No sign-in needed.
TrustScan's tools are live in every AI client you've connected — with rules and logging built in.
Free to start · No credit card · No hosting needed
Fetched live from the official endpoint and re-checked daily by gate — not marketing copy.
trust_scan_server — Security-scan an MCP server or skill package before trusting it. Runs all four checks — invisible Unicode prompt-injection, dangerous code
trust_scan_file — Security-scan a single file for invisible Unicode, dangerous patterns, and secrets. Returns a severity-weighted score and per-finding detai
https://trust-scan-production.up.railway.app/mcp/Yes — TrustScan operates its own remote MCP server at trust-scan-production.up.railway.app. gate connects you to that official endpoint and adds security scanning, per-tool access rules, and an activity log on top.
Add gate's gateway URL to your AI client once, then pick TrustScan in the directory. No account or sign-in is needed. From then on, TrustScan's tools are available in every client you've connected to gate.
No. TrustScan runs the server, and gate is fully managed. You just connect one URL — there's nothing to install, deploy, or maintain.
It's the vendor's official endpoint, and gate scans its tools for prompt injection and hidden instructions before it goes live, re-checks it whenever it changes, and lets you allow, block, or require approval for every single tool.
Yes — you can get started with gate for free and connect TrustScan in minutes. No credit card required.
Every server below works through the same gateway URL — connect once, add tools anytime.
Set up TrustScan in: Claude · Claude Code · ChatGPT · Cursor · VS Code