MCP低风险未认领
TAR Engine
Audit AI skill safety before you ship. Static, semantic, adversarial, supply chain scans.
qingxuantangqingxuantang/tar-engine
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.qingxuantang/tar-engine",
"description": "Audit AI skill safety before you ship. Static, semantic, adversarial, supply chain scans.",
"title": "TAR Engine",
"repository": {
"url": "https://github.com/qingxuantang/tar-engine",
"source": "github"
},
"version": "0.3.3",
"websiteUrl": "https://tarai.dev",
"packages": [
{
"registryType": "pypi",
"identifier": "tar-engine",
"version": "0.3.3",
"runtimeHint": "uvx",
"transport": {
"type": "stdio"
},
"packageArguments": [
{
"description": "Install the tar-engine wheel that provides the tar-engine-mcp executable.",
"value": "tar-engine",
"type": "positional",
"name": "--from"
},
{
"description": "Run the MCP server entry point exposed by the tar-engine wheel.",
"value": "tar-engine-mcp",
"type": "positional",
"name": "tar-engine-mcp"
}
],
"environmentVariables": [
{
"description": "Override the audit backend. Default is the hosted playground at https://tarai.dev. Set to http://localhost:8765 (or your own tar-engine deployment) to self-host and keep SKILL.md content on your machine.",
"name": "TAR_ENGINE_URL"
},
{
"description": "OpenAI API key that unlocks the semantic LLM and adversarial prompt-fuzz layers. Static and supply-chain layers run without it.",
"isSecret": true,
"name": "TAR_ENGINE_BYOK_OPENAI_KEY"
},
{
"description": "Anthropic API key alternative to the OpenAI key for the semantic and adversarial layers.",
"isSecret": true,
"name": "TAR_ENGINE_BYOK_ANTHROPIC_KEY"
}
]
}
]
}权限
声明检测
运行代码—
python安装—
pypi:tar-engine@0.3.3安装时运行脚本—无
网络无无
需要的凭据
TAR_ENGINE_BYOK_ANTHROPIC_KEYTAR_ENGINE_BYOK_OPENAI_KEYTAR_ENGINE_BYOK_ANTHROPIC_KEYTAR_ENGINE_BYOK_OPENAI_KEY工作区外的路径—无
智能体工具—无
检查
低风险 · 没有发现需要提醒的地方。
未经人工审核 · 已做规则检查;模型审核尚未开启。
版本
- #10.3.3最新2026年10月7日
TAR Engine在 Codeg 中打开