MCP低风险未认领

TAR Engine

Audit AI skill safety before you ship. Static, semantic, adversarial, supply chain scans.

qingxuantangqingxuantang/tar-engine★ 2更新于 2026年7月23日

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.qingxuantang/tar-engine",
  "description": "Audit AI skill safety before you ship. Static, semantic, adversarial, supply chain scans.",
  "title": "TAR Engine",
  "repository": {
    "url": "https://github.com/qingxuantang/tar-engine",
    "source": "github"
  },
  "version": "0.3.3",
  "websiteUrl": "https://tarai.dev",
  "packages": [
    {
      "registryType": "pypi",
      "identifier": "tar-engine",
      "version": "0.3.3",
      "runtimeHint": "uvx",
      "transport": {
        "type": "stdio"
      },
      "packageArguments": [
        {
          "description": "Install the tar-engine wheel that provides the tar-engine-mcp executable.",
          "value": "tar-engine",
          "type": "positional",
          "name": "--from"
        },
        {
          "description": "Run the MCP server entry point exposed by the tar-engine wheel.",
          "value": "tar-engine-mcp",
          "type": "positional",
          "name": "tar-engine-mcp"
        }
      ],
      "environmentVariables": [
        {
          "description": "Override the audit backend. Default is the hosted playground at https://tarai.dev. Set to http://localhost:8765 (or your own tar-engine deployment) to self-host and keep SKILL.md content on your machine.",
          "name": "TAR_ENGINE_URL"
        },
        {
          "description": "OpenAI API key that unlocks the semantic LLM and adversarial prompt-fuzz layers. Static and supply-chain layers run without it.",
          "isSecret": true,
          "name": "TAR_ENGINE_BYOK_OPENAI_KEY"
        },
        {
          "description": "Anthropic API key alternative to the OpenAI key for the semantic and adversarial layers.",
          "isSecret": true,
          "name": "TAR_ENGINE_BYOK_ANTHROPIC_KEY"
        }
      ]
    }
  ]
}

权限

声明检测
运行代码—python
安装—pypi:tar-engine@0.3.3
安装时运行脚本—无
网络无无
需要的凭据TAR_ENGINE_BYOK_ANTHROPIC_KEYTAR_ENGINE_BYOK_OPENAI_KEYTAR_ENGINE_BYOK_ANTHROPIC_KEYTAR_ENGINE_BYOK_OPENAI_KEY
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

版本

  1. #10.3.3最新2026年10月7日