Security-first MCP server. Sanitizes web content before it reaches your LLM — strips prompt injection, redacts PII, and reduces token consumption by up to 70%.
Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.
forge verify visus-mcpDie Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.
visus_context_scanDetect multi-turn priming risks in conversation history (e.g., "save this URL from Page 1" used in Page 2 tool call).
Scans for stateful chaining attacks. Use before visus_fetch/visus_search when suspicious.
Provides risk score (0-1), primed entities (hashed URLs/IPs/tools), and threats.
High ri…Detect multi-turn priming risks in conversation history (e.g., "save this URL from Page 1" used in Page 2 tool call). Scans for stateful chaining attacks. Use before visus_fetch/visus_search when suspicious. Provides risk score (0-1), primed entities (hashed URLs/IPs/tools), and threats. High ri…
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
visus_db_verifyVerify and sanitize DB terms for RCE (CVE-2026-32622)Verify and sanitize DB terms for RCE (CVE-2026-32622)
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
visus_fetch_structuredFetch a web page and extract structured data according to a schema. SECURITY: All extracted fields pass through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE being returned to the LLM. Each field is independently sanitized to ensure safe consumption of untrusted web…Fetch a web page and extract structured data according to a schema. SECURITY: All extracted fields pass through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE being returned to the LLM. Each field is independently sanitized to ensure safe consumption of untrusted web…
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
visus_fetchFetch and sanitize web page content. Returns clean, injection-free content in markdown or text format. SECURITY: All content passes through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE reaching the LLM. This ensures safe consumption of untrusted web content.Fetch and sanitize web page content. Returns clean, injection-free content in markdown or text format. SECURITY: All content passes through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE reaching the LLM. This ensures safe consumption of untrusted web content.
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
visus_get_ledger_proofRetrieve tamper-evident proof for a specific request ID, including event details and Merkle inclusion proof for audit verification.Retrieve tamper-evident proof for a specific request ID, including event details and Merkle inclusion proof for audit verification.
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
visus_scan_mcpScan MCP server configuration parameters for security risks before spawning. Pass config as JSON string: {command?: string, args?: string[], env?: object}. Returns findings, score, and remediation advice.Scan MCP server configuration parameters for security risks before spawning. Pass config as JSON string: {command?: string, args?: string[], env?: object}. Returns findings, score, and remediation advice.
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
comment_injectionInstructions hidden in HTML/JS/SQL commentsInstructions hidden in HTML/JS/SQL comments
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
direct_instruction_injectionInjektionsrisikoAttempts to override or ignore previous instructionsAttempts to override or ignore previous instructions
Attempts to override or ignore previous instructionsFür dieses Tool wurde kein Eingabeschema veröffentlicht.
role_hijackingAttempts to change AI persona or roleAttempts to change AI persona or role
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
system_prompt_extractionAttempts to reveal system instructionsAttempts to reveal system instructions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
privilege_escalationAttempts to gain elevated permissionsAttempts to gain elevated permissions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
context_poisoningFalsely claims prior agreement or contextFalsely claims prior agreement or context
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
data_exfiltrationAttempts to send data to external endpointsAttempts to send data to external endpoints
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
base64_obfuscationBase64-encoded instructionsBase64-encoded instructions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
unicode_lookalikesUses visually similar Unicode charactersUses visually similar Unicode characters
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
zero_width_charactersHidden zero-width Unicode charactersHidden zero-width Unicode characters
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
glassworm_unicode_clustersGlassworm-style steganographic attacks using invisible Unicode Variation SelectorsGlassworm-style steganographic attacks using invisible Unicode Variation Selectors
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
html_script_injectionHTML script tags or event handlersHTML script tags or event handlers
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
data_uri_injectionData URIs that could contain instructionsData URIs that could contain instructions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
markdown_link_injectionMalicious markdown linksMalicious markdown links
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
url_fragment_hashjackInstructions hidden in URL fragmentsInstructions hidden in URL fragments
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
social_engineering_urgencyUrgency language to bypass cautionUrgency language to bypass caution
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
instruction_delimiter_injectionFake instruction boundariesFake instruction boundaries
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
multi_language_obfuscationInstructions in non-English using English keywordsInstructions in non-English using English keywords
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
reverse_text_obfuscationInstructions written backwardsInstructions written backwards
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
leetspeak_obfuscationL33tspeak encoded instructionsL33tspeak encoded instructions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
jailbreak_keywordsCommon jailbreak attempt keywordsCommon jailbreak attempt keywords
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
token_smugglingAttempts to inject special tokensAttempts to inject special tokens
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
system_message_injectionFake system messagesFake system messages
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
conversation_resetAttempts to reset conversation stateAttempts to reset conversation state
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
memory_manipulationAttempts to manipulate AI memory or implant false contextAttempts to manipulate AI memory or implant false context
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
capability_probingProbes for hidden capabilitiesProbes for hidden capabilities
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
chain_of_thought_manipulationManipulates reasoning processManipulates reasoning process
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
hypothetical_scenario_injectionUses hypotheticals to bypass restrictionsUses hypotheticals to bypass restrictions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
ethical_overrideAttempts to override ethical guidelinesAttempts to override ethical guidelines
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
output_format_manipulationManipulates output format to hide instructionsManipulates output format to hide instructions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
negative_instructionUses negation to inject instructionsUses negation to inject instructions
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
credential_harvestingAttempts to harvest credentialsAttempts to harvest credentials
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
time_based_triggersConditional execution based on timeConditional execution based on time
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
code_execution_requestsRequests code execution or contains dangerous code patternsRequests code execution or contains dangerous code patterns
Für dieses Tool wurde kein Eingabeschema veröffentlicht.
40 von 40 Tools haben eine Beschreibung veröffentlicht.
Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.
Security-first MCP server. Sanitizes web content before it reaches your LLM — strips prompt injection, redacts PII, and reduces token consumption by up to 70%.
Verlinkte Namen öffnen den Forge-Index aller Einträge, bei denen dieses Tool beobachtet wurde. Alle indexierten Tools durchsuchen.
Der Durchlauf endete an der Grenze von 60 Paketen. Der Rest des Baums wurde nie aufgelöst.
36 weitere aufgelöste Pakete werden hier nicht gezeichnet (Anzeigegrenze: 24). Jede Abhängigkeit mit einem Sicherheitshinweis wird unabhängig von der Grenze gezeichnet. Vollständiges Inventar (CycloneDX-SBOM)
80 deklarierte Abhängigkeiten sind nie im Baum gelandet. Sie fehlen in Forges Auflösung, nicht im Paket.
+68 weitere nicht aufgeführt. Die Zählungen nach Grund oben erfassen sie alle.
Nicht verfolgt: peerDependencies, optionalDependencies. Dieser Baum erfasst nur Laufzeitabhängigkeiten; was jene mitbringen, wurde nie aufgelöst.