Security-first MCP server. Sanitizes web content before it reaches your LLM — strips prompt injection, redacts PII, and reduces token consumption by up to 70%.
Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.
forge verify visus-mcpLa vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.
Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.
visus_context_scanDetect multi-turn priming risks in conversation history (e.g., "save this URL from Page 1" used in Page 2 tool call).
Scans for stateful chaining attacks. Use before visus_fetch/visus_search when suspicious.
Provides risk score (0-1), primed entities (hashed URLs/IPs/tools), and threats.
High ri…Detect multi-turn priming risks in conversation history (e.g., "save this URL from Page 1" used in Page 2 tool call). Scans for stateful chaining attacks. Use before visus_fetch/visus_search when suspicious. Provides risk score (0-1), primed entities (hashed URLs/IPs/tools), and threats. High ri…
Aucun schéma d’entrée n’a été publié pour cet outil.
visus_db_verifyVerify and sanitize DB terms for RCE (CVE-2026-32622)Verify and sanitize DB terms for RCE (CVE-2026-32622)
Aucun schéma d’entrée n’a été publié pour cet outil.
visus_fetch_structuredFetch a web page and extract structured data according to a schema. SECURITY: All extracted fields pass through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE being returned to the LLM. Each field is independently sanitized to ensure safe consumption of untrusted web…Fetch a web page and extract structured data according to a schema. SECURITY: All extracted fields pass through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE being returned to the LLM. Each field is independently sanitized to ensure safe consumption of untrusted web…
Aucun schéma d’entrée n’a été publié pour cet outil.
visus_fetchFetch and sanitize web page content. Returns clean, injection-free content in markdown or text format. SECURITY: All content passes through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE reaching the LLM. This ensures safe consumption of untrusted web content.Fetch and sanitize web page content. Returns clean, injection-free content in markdown or text format. SECURITY: All content passes through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE reaching the LLM. This ensures safe consumption of untrusted web content.
Aucun schéma d’entrée n’a été publié pour cet outil.
visus_get_ledger_proofRetrieve tamper-evident proof for a specific request ID, including event details and Merkle inclusion proof for audit verification.Retrieve tamper-evident proof for a specific request ID, including event details and Merkle inclusion proof for audit verification.
Aucun schéma d’entrée n’a été publié pour cet outil.
visus_scan_mcpScan MCP server configuration parameters for security risks before spawning. Pass config as JSON string: {command?: string, args?: string[], env?: object}. Returns findings, score, and remediation advice.Scan MCP server configuration parameters for security risks before spawning. Pass config as JSON string: {command?: string, args?: string[], env?: object}. Returns findings, score, and remediation advice.
Aucun schéma d’entrée n’a été publié pour cet outil.
comment_injectionInstructions hidden in HTML/JS/SQL commentsInstructions hidden in HTML/JS/SQL comments
Aucun schéma d’entrée n’a été publié pour cet outil.
direct_instruction_injectionrisque d’injectionAttempts to override or ignore previous instructionsAttempts to override or ignore previous instructions
Attempts to override or ignore previous instructionsAucun schéma d’entrée n’a été publié pour cet outil.
role_hijackingAttempts to change AI persona or roleAttempts to change AI persona or role
Aucun schéma d’entrée n’a été publié pour cet outil.
system_prompt_extractionAttempts to reveal system instructionsAttempts to reveal system instructions
Aucun schéma d’entrée n’a été publié pour cet outil.
privilege_escalationAttempts to gain elevated permissionsAttempts to gain elevated permissions
Aucun schéma d’entrée n’a été publié pour cet outil.
context_poisoningFalsely claims prior agreement or contextFalsely claims prior agreement or context
Aucun schéma d’entrée n’a été publié pour cet outil.
data_exfiltrationAttempts to send data to external endpointsAttempts to send data to external endpoints
Aucun schéma d’entrée n’a été publié pour cet outil.
base64_obfuscationBase64-encoded instructionsBase64-encoded instructions
Aucun schéma d’entrée n’a été publié pour cet outil.
unicode_lookalikesUses visually similar Unicode charactersUses visually similar Unicode characters
Aucun schéma d’entrée n’a été publié pour cet outil.
zero_width_charactersHidden zero-width Unicode charactersHidden zero-width Unicode characters
Aucun schéma d’entrée n’a été publié pour cet outil.
glassworm_unicode_clustersGlassworm-style steganographic attacks using invisible Unicode Variation SelectorsGlassworm-style steganographic attacks using invisible Unicode Variation Selectors
Aucun schéma d’entrée n’a été publié pour cet outil.
html_script_injectionHTML script tags or event handlersHTML script tags or event handlers
Aucun schéma d’entrée n’a été publié pour cet outil.
data_uri_injectionData URIs that could contain instructionsData URIs that could contain instructions
Aucun schéma d’entrée n’a été publié pour cet outil.
markdown_link_injectionMalicious markdown linksMalicious markdown links
Aucun schéma d’entrée n’a été publié pour cet outil.
url_fragment_hashjackInstructions hidden in URL fragmentsInstructions hidden in URL fragments
Aucun schéma d’entrée n’a été publié pour cet outil.
social_engineering_urgencyUrgency language to bypass cautionUrgency language to bypass caution
Aucun schéma d’entrée n’a été publié pour cet outil.
instruction_delimiter_injectionFake instruction boundariesFake instruction boundaries
Aucun schéma d’entrée n’a été publié pour cet outil.
multi_language_obfuscationInstructions in non-English using English keywordsInstructions in non-English using English keywords
Aucun schéma d’entrée n’a été publié pour cet outil.
reverse_text_obfuscationInstructions written backwardsInstructions written backwards
Aucun schéma d’entrée n’a été publié pour cet outil.
leetspeak_obfuscationL33tspeak encoded instructionsL33tspeak encoded instructions
Aucun schéma d’entrée n’a été publié pour cet outil.
jailbreak_keywordsCommon jailbreak attempt keywordsCommon jailbreak attempt keywords
Aucun schéma d’entrée n’a été publié pour cet outil.
token_smugglingAttempts to inject special tokensAttempts to inject special tokens
Aucun schéma d’entrée n’a été publié pour cet outil.
system_message_injectionFake system messagesFake system messages
Aucun schéma d’entrée n’a été publié pour cet outil.
conversation_resetAttempts to reset conversation stateAttempts to reset conversation state
Aucun schéma d’entrée n’a été publié pour cet outil.
memory_manipulationAttempts to manipulate AI memory or implant false contextAttempts to manipulate AI memory or implant false context
Aucun schéma d’entrée n’a été publié pour cet outil.
capability_probingProbes for hidden capabilitiesProbes for hidden capabilities
Aucun schéma d’entrée n’a été publié pour cet outil.
chain_of_thought_manipulationManipulates reasoning processManipulates reasoning process
Aucun schéma d’entrée n’a été publié pour cet outil.
hypothetical_scenario_injectionUses hypotheticals to bypass restrictionsUses hypotheticals to bypass restrictions
Aucun schéma d’entrée n’a été publié pour cet outil.
ethical_overrideAttempts to override ethical guidelinesAttempts to override ethical guidelines
Aucun schéma d’entrée n’a été publié pour cet outil.
output_format_manipulationManipulates output format to hide instructionsManipulates output format to hide instructions
Aucun schéma d’entrée n’a été publié pour cet outil.
negative_instructionUses negation to inject instructionsUses negation to inject instructions
Aucun schéma d’entrée n’a été publié pour cet outil.
credential_harvestingAttempts to harvest credentialsAttempts to harvest credentials
Aucun schéma d’entrée n’a été publié pour cet outil.
time_based_triggersConditional execution based on timeConditional execution based on time
Aucun schéma d’entrée n’a été publié pour cet outil.
code_execution_requestsRequests code execution or contains dangerous code patternsRequests code execution or contains dangerous code patterns
Aucun schéma d’entrée n’a été publié pour cet outil.
40 outils sur 40 ont publié une description.
Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.
Security-first MCP server. Sanitizes web content before it reaches your LLM — strips prompt injection, redacts PII, and reduces token consumption by up to 70%.
Les noms cliquables ouvrent l’index Forge de toutes les entrées observées exposant cet outil. Parcourir tous les outils indexés.
L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.
36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)
80 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.
+68 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.
Non suivies : peerDependencies, optionalDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.