# Mcptrustchecker

> Local-first, deterministic security scanner for Model Context Protocol (MCP) servers. Cross-tool toxic-flow analysis, Unicode-smuggling decode, prompt-injection & supply-chain detection, with an auditable 0–100 Trust Score.

## Facts
- Page: https://tashan.sh/capability/pkg-mcptrustchecker
- tashan id: pkg:mcptrustchecker
- Source: https://github.com/illiahaidar/mcptrustchecker
- npm: https://www.npmjs.com/package/mcptrustchecker
- Type: npm
- Category: security
- tashan score: 54.0 / 100
- Adoption: 29.0
- Upkeep: 66.0
- Freshness: 93.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- npm downloads: 114/week
- Official: no

## Install

```sh
claude mcp add mcptrustchecker -- npx -y mcptrustchecker
```

## Security audit
- Known advisories: 0
- Install-time script: none declared
- Build provenance: not attested

Permissions are read from DECLARED dependencies only. Nothing is executed, so an empty result means "nothing declared", never "nothing possible".

---
Measured 2026-08-15 by tashan (https://tashan.sh) from public evidence. Scorer s5.
