Hallucination & safety checks for LLM/Agent outputs: claim-level fact-check with citations.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
English | 在线体验 | 官方 MCP Registry | 魔搭 MCP 广场 | Coze 商店
给 AI 装上「事实核验 + 安全网关」:逐声明幻觉检测、Agent 轨迹六维评估、CUA 动作 L0-L3 风险分级、Agent 源码静态审计、40+ 特征注入/越狱拦截——一个 MCP server,五个工具,接入 Claude Code / Cursor / Claude Desktop。
| 工具 | 后端端点 | 作用 | 耗额度 |
|---|---|---|---|
verify_text | POST /detect | 逐声明幻觉核验:返回红/黄/绿汇总 + 每条声明 status/confidence/reason/sources + citations | ✅ detect |
verify_agent | POST /detect-agent | agent 最终输出文本级核验 + 执行轨迹六维评估(事实性/来源/指令合规/工具声明一致/任务完成/反思) | ✅ detect |
check_cua_actions | POST /cua/classify | Computer-Use Agent 动作风险分级 L0-L3 + takeover(凭据场景挂起);覆盖敏感路径/破坏性命令、域名分级、支付金额阈值、task_scope 任务意图偏离、多智能体委托链跨跳污点分析;响应含 ruleset_version 与 disclaimer(纯规则,无 LLM) | ❌ 不耗 |
check_cua_code_audit | POST /cua/audit-code | Agent 源码静态审计:危险导入 / 权限边界 / 注入面 / 危险默认值 / 沙箱缺失 | ❌ 不耗 |
check_safety | POST /guard/check(fast=true → /guard/check-fast) | 40+ 特征安全网关:Prompt 注入 / 越狱 / 有害内容 / 敏感信息泄露 / 欺诈 | ✅ detect |
鉴权模型:客户端在各自机器配
Authorization: Bearer <你的 HallucC API key>头 → server 提取并原样透传到后端 → 后端校验 + 扣同一账号额度。key 只在 HTTP 头里流转,不进工具参数、不进模型 transcript。
check_cua_actions 的收窄能力| 字段 | 作用 |
|---|---|
actions[].target_url / url | 浏览器动作目标 URL——未知域导航升 L2、粘贴敏感内容到非白名单域升 L3、黑名单域 L3 |
task_scope.task | 声明任务意图,供偏离检测与审计留痕 |
task_scope.allowed_apps / allowed_domains | 允许的应用/域名(域名后缀匹配含子域) |
task_scope.forbidden_elements | 禁止的元素标签(优先级最高) |
actions[].chain_id | 多智能体委托链 id(uuid hex)——给了则响应追加 chain_trace 链级跨跳污点分析 |
actions[].agent_id / parent_agent_id | 本动作所属 Agent / 委托方 Agent,跨 agent 边界的传播链由此配对 |
actions[].delegation_depth | 委托深度(根 Agent=0),子 Agent 外发命中敏感模式内容会追加 L2 |
任务越出 task_scope 时升一级处置(L0→L1、L1→L2、L2 保持但追加「超出任务范围」、L3 不变);
该机制只能收窄不可放宽,不传 task_scope 则零影响。凭据字段与支付/登录域会产出 takeover 裁决
(挂起等用户亲手输入,agent 不替用户输密码)。
多智能体场景(Claude Code Task 子代理 / Codex agents / Kimi 等):父 Agent 读密钥文件(单看 L0)→
子 Agent 外发(单看 L2)每跳单独无害、链路整体高危。每条动作带上委托链字段后,服务端会追加
chain_trace:跨 agent 传播存在时链路聚合级别抬到 L3 并置 risk_diluted(洗白信号)。
链字段不传则完全零影响——老调用方无需任何改动。
响应体的 ruleset_version 可用于核对在线检测与本地 Gate 是否同版规则。
MCP server 已部署在 https://aihcc.cloud/mcp(remote,streamable-http)。客户端直接配公网地址 + 个人 API key 即可:
Cursor / Claude Desktop 同理,URL 填 https://aihcc.cloud/mcp,Headers 加 Authorization: Bearer <key>。API key 在 https://aihcc.cloud 注册后于 /keys 页创建,免费套餐每日有额度。
同一套工具,走 stdio 传输,key 从环境变量读取,默认连公网后端 https://aihcc.cloud/api。
base 必须带
/api前缀:nginx 只把/api/代理到后端。填裸域名https://aihcc.cloud会打到前端页面, 返回 200 但 body 是 HTML——请求静默失败(审计不落库、不落兜底文件),审计回放里看不到任何记录。
服务监听 http://127.0.0.1:8787/mcp,健康检查 GET /health。
Settings → MCP → Add MCP server:
httphttp://127.0.0.1:8787/mcp{"Authorization": "Bearer <你的 HallucC API key>"}~/Library/Application Support/Claude/claude_desktop_config.json:
Authorization 头或 key 无效 → MCP 层返回 401 JSON-RPC 错误。quota 对象 = 后端 quota_status,与 Web 仪表盘同源、随调用递减。check_cua_actions 与 check_cua_code_audit 均为纯规则,不调 LLM、不耗额度,可放心高频调用。Streamable HTTP(当前 MCP 规范推荐的 remote 传输,即「HTTP+SSE」),stateless 模式:每个 POST 新建 transport + McpServer,处理完即关。Claude Code / Cursor / Claude Desktop 均原生支持。后续若要兼容只认旧版 SSE 的客户端,加 SSEServerTransport(双端点 /sse + /messages)即可。
io.github.fredyee/hallucc v0.1.1(active)No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/hallucc-hallucination-safety-guardian)<a href="https://allmcps.com/mcp/hallucc-hallucination-safety-guardian"><img src="https://allmcps.com/api/badge/hallucc-hallucination-safety-guardian?style=directory" alt="HallucC — Hallucination & Safety Guardian on AllMCPs" /></a>