Skip to content
Windsurf

TrustScan for Windsurf

io.github.entradox/trust-scan

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

client:Windsurf transport:streamable-http tools:4

Install TrustScan in Windsurf

~/.codeium/windsurf/mcp_config.json · windows: %USERPROFILE%\.codeium\windsurf\mcp_config.json

{
  "mcpServers": {
    "trust-scan": {
      "serverUrl": "https://trust-scan-production.up.railway.app/mcp/"
    }
  }
}

Global only — Windsurf has no per-project MCP config. Refresh Cascade after saving. Windsurf docs

What Windsurf can do once it is connected

TrustScan in other clients