visus-mcp

MCPcommunity
v0.27.0Roongrunchai ChongolneeMITUpdated 5mo agonpmGitHub

Security-first MCP server. Sanitizes web content before it reaches your LLM — strips prompt injection, redacts PII, and reduces token consumption by up to 70%.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
139Downloads/wk
5mo agoLast update
Package
AuthorRoongrunchai Chongolnee
LicenseMIT
Version0.27.0
Sourcenpm+mcp-registry
Trust Status
C
40/100Caution
Listed in Forge index+10/10
Publisher identity verified+0/20
Publisher: run `forge publish` from the package repo to claim ownership
Ed25519 publish signature+0/5
Included automatically when the publisher runs `forge publish`
Domain verification+0/5
Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+0/5
Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
npm maintainer match+0/5
Earned once your identity is verified above and that login is an npm maintainer of this package
CVE scan · clean+30/30
Static analysis · clean+0/20
Suspicious install scripts or obfuscated code detected
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain
Provenance
Dependencies60 resolved · 2 with advisories
Tool surface40 tools · none privileged
Security scan⚠ Warnings (6)v0.27.0 · 3d agoHow well does this scan work?
PROMPTtool:direct_instruction_injectionInstruction-override phrase
EvalsNone
IndexedAug 27, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · none privileged · 1 flagged for injection
Statically extracted from the published packagev0.27.0 · 3d ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

visus_context_scanDetect multi-turn priming risks in conversation history (e.g., "save this URL from Page 1" used in Page 2 tool call). Scans for stateful chaining attacks. Use before visus_fetch/visus_search when suspicious. Provides risk score (0-1), primed entities (hashed URLs/IPs/tools), and threats. High ri…

Detect multi-turn priming risks in conversation history (e.g., "save this URL from Page 1" used in Page 2 tool call). Scans for stateful chaining attacks. Use before visus_fetch/visus_search when suspicious. Provides risk score (0-1), primed entities (hashed URLs/IPs/tools), and threats. High ri…

No input schema was published for this tool.

visus_db_verifyVerify and sanitize DB terms for RCE (CVE-2026-32622)

Verify and sanitize DB terms for RCE (CVE-2026-32622)

No input schema was published for this tool.

visus_fetch_structuredFetch a web page and extract structured data according to a schema. SECURITY: All extracted fields pass through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE being returned to the LLM. Each field is independently sanitized to ensure safe consumption of untrusted web…

Fetch a web page and extract structured data according to a schema. SECURITY: All extracted fields pass through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE being returned to the LLM. Each field is independently sanitized to ensure safe consumption of untrusted web…

No input schema was published for this tool.

visus_fetchFetch and sanitize web page content. Returns clean, injection-free content in markdown or text format. SECURITY: All content passes through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE reaching the LLM. This ensures safe consumption of untrusted web content.

Fetch and sanitize web page content. Returns clean, injection-free content in markdown or text format. SECURITY: All content passes through prompt injection sanitization (43 pattern categories) and PII redaction BEFORE reaching the LLM. This ensures safe consumption of untrusted web content.

No input schema was published for this tool.

visus_get_ledger_proofRetrieve tamper-evident proof for a specific request ID, including event details and Merkle inclusion proof for audit verification.

Retrieve tamper-evident proof for a specific request ID, including event details and Merkle inclusion proof for audit verification.

No input schema was published for this tool.

visus_scan_mcpScan MCP server configuration parameters for security risks before spawning. Pass config as JSON string: {command?: string, args?: string[], env?: object}. Returns findings, score, and remediation advice.

Scan MCP server configuration parameters for security risks before spawning. Pass config as JSON string: {command?: string, args?: string[], env?: object}. Returns findings, score, and remediation advice.

No input schema was published for this tool.

comment_injectionInstructions hidden in HTML/JS/SQL comments

Instructions hidden in HTML/JS/SQL comments

No input schema was published for this tool.

direct_instruction_injectioninjection riskAttempts to override or ignore previous instructions

Attempts to override or ignore previous instructions

INJECTIONInstruction-override phraseAttempts to override or ignore previous instructions

No input schema was published for this tool.

role_hijackingAttempts to change AI persona or role

Attempts to change AI persona or role

No input schema was published for this tool.

system_prompt_extractionAttempts to reveal system instructions

Attempts to reveal system instructions

No input schema was published for this tool.

privilege_escalationAttempts to gain elevated permissions

Attempts to gain elevated permissions

No input schema was published for this tool.

context_poisoningFalsely claims prior agreement or context

Falsely claims prior agreement or context

No input schema was published for this tool.

data_exfiltrationAttempts to send data to external endpoints

Attempts to send data to external endpoints

No input schema was published for this tool.

base64_obfuscationBase64-encoded instructions

Base64-encoded instructions

No input schema was published for this tool.

unicode_lookalikesUses visually similar Unicode characters

Uses visually similar Unicode characters

No input schema was published for this tool.

zero_width_charactersHidden zero-width Unicode characters

Hidden zero-width Unicode characters

No input schema was published for this tool.

glassworm_unicode_clustersGlassworm-style steganographic attacks using invisible Unicode Variation Selectors

Glassworm-style steganographic attacks using invisible Unicode Variation Selectors

No input schema was published for this tool.

html_script_injectionHTML script tags or event handlers

HTML script tags or event handlers

No input schema was published for this tool.

data_uri_injectionData URIs that could contain instructions

Data URIs that could contain instructions

No input schema was published for this tool.

markdown_link_injectionMalicious markdown links

Malicious markdown links

No input schema was published for this tool.

url_fragment_hashjackInstructions hidden in URL fragments

Instructions hidden in URL fragments

No input schema was published for this tool.

social_engineering_urgencyUrgency language to bypass caution

Urgency language to bypass caution

No input schema was published for this tool.

instruction_delimiter_injectionFake instruction boundaries

Fake instruction boundaries

No input schema was published for this tool.

multi_language_obfuscationInstructions in non-English using English keywords

Instructions in non-English using English keywords

No input schema was published for this tool.

reverse_text_obfuscationInstructions written backwards

Instructions written backwards

No input schema was published for this tool.

leetspeak_obfuscationL33tspeak encoded instructions

L33tspeak encoded instructions

No input schema was published for this tool.

jailbreak_keywordsCommon jailbreak attempt keywords

Common jailbreak attempt keywords

No input schema was published for this tool.

token_smugglingAttempts to inject special tokens

Attempts to inject special tokens

No input schema was published for this tool.

system_message_injectionFake system messages

Fake system messages

No input schema was published for this tool.

conversation_resetAttempts to reset conversation state

Attempts to reset conversation state

No input schema was published for this tool.

memory_manipulationAttempts to manipulate AI memory or implant false context

Attempts to manipulate AI memory or implant false context

No input schema was published for this tool.

capability_probingProbes for hidden capabilities

Probes for hidden capabilities

No input schema was published for this tool.

chain_of_thought_manipulationManipulates reasoning process

Manipulates reasoning process

No input schema was published for this tool.

hypothetical_scenario_injectionUses hypotheticals to bypass restrictions

Uses hypotheticals to bypass restrictions

No input schema was published for this tool.

ethical_overrideAttempts to override ethical guidelines

Attempts to override ethical guidelines

No input schema was published for this tool.

output_format_manipulationManipulates output format to hide instructions

Manipulates output format to hide instructions

No input schema was published for this tool.

negative_instructionUses negation to inject instructions

Uses negation to inject instructions

No input schema was published for this tool.

credential_harvestingAttempts to harvest credentials

Attempts to harvest credentials

No input schema was published for this tool.

time_based_triggersConditional execution based on time

Conditional execution based on time

No input schema was published for this tool.

code_execution_requestsRequests code execution or contains dangerous code patterns

Requests code execution or contains dangerous code patterns

No input schema was published for this tool.

40 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Security-first MCP server. Sanitizes web content before it reaches your LLM — strips prompt injection, redacts PII, and reduces token consumption by up to 70%.

Keywords
mcpclaudeweb-fetchsecurityprompt-injectionpii-redactionanthropic
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-08-30 — observed resolution, not a publisher declaration.

60 packages resolved · 15 direct · 2 carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

80 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+68 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies, optionalDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.

Topics

Related in security