Formally-verified injection/exfiltration detector for AI agents (MCP-02).
Listed on
- Official MCP Registry
- PulseMCPvia MCP Toplist
First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.
2
Directories
1 via MCP Toplist
2
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
0
GitHub stars
From MCP Toplist
Tools
| Tool | Description | Behaviour |
|---|---|---|
| detect_injection | Screen untrusted input for prompt/tool injection, exfiltration, and obfuscation before an agent consumes it. Returns a verdict (clean|suspicious|attack), probability, bits-at-risk (upper bound on adversarial capture per the Adversarial Landauer bound), matched canon patterns, and a recommended action (allow|sanitize|reject|escalate). Backed by Aristotle-verified theorems T-IB-02/T-IB-06/T-IB-01. | Not declared |
| detect_trace_tool_policy | Analyze an agent trace for the Gray Swan Wave 16 class: untrusted retrieved/tool output causing a tool call outside the user-declared per-turn allowlist. Returns trace counts, unauthorized tool-call evidence, canon mapping VC-AI-TOOL-0001, and claim-boundary guardrails. Backed by T-IB-25/T-IB-29/T-IB-36. | Not declared |
| Directory | Listing | Tier | First seen |
|---|---|---|---|
| Official MCP Registry | io.github.viridis-security/injection-detector | - | 2 Oct 2026 |
| PulseMCP | Listed there according to MCP Toplist’s dataset; not collected by InvokeRank. | ||