Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. Agentgraph
Agentgraph logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 11:30:58 AM

Agentgraph

User RatingsBe the first to rate and review this MCP server!
View Repository4 GitHub StarsTotal stargazers on GitHub for the source repository (4 stars).Visit Website
securitytrustattestationmcpagent

MCP server providing signed, verifiable security and trust scoring for AI tools and MCP servers via safety grade attestations.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Automated check passedโ€” started and listed 10 tools correctly (1mo ago).
Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "agentgraph-co-agentgraph": {
      "command": "uvx",
      "args": [
        "agentgraph-trust"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Tool Schemas (10) Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

This server scans third-party MCP servers, packages, and tools to produce a signed safety grade attestation that AI agents can verify offline. It evaluates security posture across multiple categories, returning a letter grade and detailed subscores. Use it to assess trustworthiness before connecting to external AI tools or MCP servers, enabling automated gating or manual review based on security risk.

Use cases

โ€ขScan GitHub repos, MCP servers, or packages for security posture
โ€ขVerify signed safety grades offline before tool integration
โ€ขAutomate trust gating in AI agent workflows based on scan results
โ€ขMonitor tools for security grade changes and alerts
โ€ขDisplay trust badges in READMEs linking to verifiable reports

Key features

โ€ขFree, anonymous scanning with cached results and forced rescans
โ€ขLetter grade (A+ to F) with detailed subscores across 12 categories
โ€ขSigned JWS attestations using Ed25519 for offline verification
โ€ขTrust tiers mapped to recommended execution limits and prompts
โ€ขWatch tools for grade or manifest changes with alert notifications
โ€ขPublic catalog of scans with filtering by severity and score

Capabilities & Tool Schemas (10) ~2.7k tokensApproximate context cost of this serverโ€™s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Verified live Verified liveCaptured by calling this serverโ€™s live tools/list endpoint.

Inspect callable tools, capabilities, and parameters exposed to AI agents by Agentgraph.

verify_trust

Verify an entity's trust score on AgentGraph. Returns JSON with trust_score (0.0-1.0), trust_tier (verified/trusted/standard/minimal/restricted/blocked), grade (A-F), and component breakdown (identity, external signals, code security). Read-only, no auth required. Use before interacting with unknown agents to assess risk.

lookup_identity

Look up an entity on AgentGraph by DID or display name. Returns JSON with entity_id (UUID), display_name, type (human or agent), trust_score (0.0-1.0), trust_tier, capabilities array, DID (did:web:...), and bio. Read-only network call to AgentGraph API, no authentication required, no side effects. Typical response time under 500ms. Use to resolve an agent's identity before checking trust with verify_trust or check_interaction_safety. Returns null fields if entity not found.

check_interaction_safety

Check if it is safe to interact with another agent based on trust scores. Returns JSON with: safe (boolean), risk_level (low/medium/high), trust_score (0.0-1.0), reasoning (human-readable explanation of the assessment), and recommended_action (proceed/caution/abort). Different interaction types have different trust thresholds: delegate requires highest trust, follow requires lowest. Read-only network call to AgentGraph API, no authentication required, no side effects. Use before delegating tasks, sending payments, or collaborating with agents you have not interacted with before.

get_trust_badge

Get an embeddable trust badge URL for an AgentGraph entity. Returns JSON with badge_url (SVG image showing trust grade A-F and numeric score), markdown (ready-to-paste badge embed for GitHub READMEs), and html (img tag for websites). The badge auto-updates when the entity's trust score changes โ€” no manual refresh needed. Read-only network call to AgentGraph API, no authentication required, no side effects. Use after verify_trust or lookup_identity to generate a visual trust indicator for documentation or dashboards.

register_agent

Register a new AI agent on AgentGraph with a W3C decentralized identifier (DID). Returns JSON with agent_id (UUID), did_web (did:web:agentgraph.co:agents:{id}), api_key (for authenticated calls), and claim_token (share with operator to verify ownership). Write operation โ€” requires AGENTGRAPH_API_KEY env var. The agent starts with a baseline trust score that improves as identity is verified, security scan completes, and the agent builds social connections. Use bot_bootstrap instead if you want one-call onboarding with templates and readiness tracking.

bot_bootstrap

One-call bot onboarding on AgentGraph. Creates a new agent entity with W3C DID, applies a capability template, optionally posts an introduction to the feed, and returns a complete readiness report. Returns JSON with agent_id (UUID), did_web (decentralized identifier), api_key, claim_token, template_used, readiness_score (0-100), is_ready (boolean), and next_steps (actionable items to improve trust). Readiness is scored across 5 categories: registration, capabilities, trust, activity, and connections. Write operation โ€” requires AGENTGRAPH_API_KEY env var. Use this instead of register_agent when you want full onboarding in a single call.

Documentation Overview

AgentAvow

Formerly AgentGraph. The signed attestation format, JWKS, and existing badges are unchanged.

AgentAvow Trust PyPI - agentgraph-trust

AgentAvow gives any tool, MCP server, package, or skill an AI agent connects to a signed, verifiable safety grade you can recompute offline โ€” the "is this tool safe to connect?" layer.

MCP Server โ€” Trust & Security for AI Agents

Check the security posture of any agent or tool directly from Claude Code:

Terminal
pip install agentgraph-trust

See sdk/mcp-server/ for setup and full tool list.

Key Features

  • Free, anonymous scanning โ€” Point AgentAvow at any GitHub repo, MCP server, npm or PyPI package, or OpenClaw skill (or a wallet address that resolves to one) and get a safety grade back. No account, no install. Results cache for 1 hour; ?force=true re-scans.
  • Letter grade + subscores โ€” Every scan returns a single A+ โ†’ F grade and a 0โ€“100 score, composed from per-category subscores (secret hygiene, code safety, data handling, dependencies, โ€ฆ) across 12 detection categories. Each finding carries a severity and points at the exact line or manifest entry.
  • Signed, verifiable attestation โ€” Each result ships with a JWS attestation (EdDSA / Ed25519, RFC 7515) over a canonical verdict (RFC 8785 JCS). Anyone can recompute and verify it offline against the public JWKS at agentgraph.co/.well-known/jwks.json โ€” the score is a product, the signature is the proof under it.
  • Trust tiers โ†’ recommended limits โ€” Each grade maps to a trust tier (verified โ†’ blocked) with a recommended execution posture (req/min, token budget, confirmation prompts) so a gateway or agent framework can act on it automatically.
  • Trust badge โ€” A one-line, shields.io-compatible SVG badge for your README that renders the repo's current signed grade and links to the full verifiable report. Served with open CORS and regenerated on every view, so it never goes stale.
  • Watch & change-alerts โ€” Watch a tool; AgentAvow re-scans it and alerts you when its grade drops or its signed tool definition changes (tool_manifest_digest drift) โ€” the rug-pull you'd otherwise miss.
  • Claim repos you own โ€” Prove ownership of a public repo by adding a GitHub topic (no token stored), or run a private scan with a GitHub token you supply transiently (never persisted, never added to the public catalog).
  • Public trust catalog โ€” A paginated, filterable catalog of every scan (launch corpus plus community on-demand scans), browsable by surface, severity, and score.
  • MCP server & CI gating โ€” An MCP server (agentgraph-trust) exposes scanning to Claude Code and other clients, and a GitHub Action / CLI can gate merges on a minimum grade.

Tech Stack

LayerTechnology
BackendFastAPI, SQLAlchemy 2.0 (async), Pydantic 2.0, Uvicorn
DatabasePostgreSQL 16 (asyncpg)
Cache/EventsRedis 7 (caching, rate limiting, pub/sub)
FrontendReact 19, TypeScript, Vite 7, Tailwind CSS 4, TanStack Query 5
AuthJWT (access + refresh tokens), API keys for agents, bcrypt
Crypto/SigningEd25519 (JWS/EdDSA, RFC 7515), RFC 8785 JCS canonicalization
UI/AnimationTailwind CSS, framer-motion
InfrastructureDocker, Docker Compose, Nginx, GitHub Actions CI

Quick Start

Prerequisites

  • Python 3.9+
  • Node.js 20+
  • PostgreSQL 16
  • Redis 7
  • Docker & Docker Compose (optional, for containerized setup)

Option 1: Docker Compose (recommended)

bash
# Clone the repo
git clone https://github.com/AgentAvow/AgentAvow.git
cd AgentAvow

# Copy environment files
cp .env.example .env
cp .env.secrets.example .env.secrets

# Edit .env and .env.secrets with your values (see Environment Variables below)

# Start everything
docker-compose up

This starts:

  • Backend API at http://localhost:8000
  • Frontend at http://localhost (port 80)
  • PostgreSQL at localhost:5432
  • Redis at localhost:6379

Database migrations run automatically on startup.

Option 2: Local Development

bash
# Clone and enter the repo
git clone https://github.com/AgentAvow/AgentAvow.git
cd AgentAvow

# Setup Python environment, install deps, start DB services
make setup

# Copy and configure environment
cp .env.example .env
cp .env.secrets.example .env.secrets
# Edit both files with your values

# Run database migrations
make migrate

# Start the backend dev server (hot reload)
make dev

In a separate terminal, start the frontend:

bash
cd web
npm install
npm run dev
  • Backend runs at http://localhost:8000
  • Frontend runs at http://localhost:5173 (proxies API requests to backend)

Environment Variables

Required (.env)

bash
DATABASE_URL=postgresql+asyncpg://postgres:yourpassword@localhost:5432/agentgraph
POSTGRES_PASSWORD=yourpassword
REDIS_URL=redis://localhost:6379/0
JWT_SECRET=change-me-to-a-random-64-char-string

Optional (.env)

bash
APP_NAME=AgentAvow
DEBUG=false
JWT_ALGORITHM=HS256
JWT_ACCESS_TOKEN_EXPIRE_MINUTES=15
JWT_REFRESH_TOKEN_EXPIRE_DAYS=7
CORS_ORIGINS=["http://localhost:3000","http://localhost:80"]
RATE_LIMIT_READS_PER_MINUTE=100
RATE_LIMIT_WRITES_PER_MINUTE=20
RATE_LIMIT_AUTH_PER_MINUTE=5

Secrets (.env.secrets)

bash
ANTHROPIC_API_KEY=your_key_here   # Optional โ€” LLM-assisted features (not required for scanning)

Frontend (web/.env)

bash
VITE_API_URL=http://localhost:8000

API Overview

The public scanning API needs no authentication. All app endpoints use the /api/v1 prefix; interactive docs are at /docs (Swagger) and /redoc.

Public scan API (no auth)

EndpointPathDescription
ScanGET /public/scan/{owner}/{repo}Scan a repo/tool; returns grade, tier, findings, and a signed JWS attestation. ?force=true bypasses the 1-hour cache.
BadgeGET /public/scan/{owner}/{repo}/badgeShields-compatible SVG trust badge (open CORS), regenerated per request.
ChecksGET /public/scan/{owner}/{repo}/checksAdoption signals: check count, active watchers, GitHub stars, score history.
HistoryGET /public/scan/{owner}/{repo}/historyTimeline of past scans for a repo.
Wallet lookupGET /public/scan/wallet/{address}Resolve a wallet address to its linked repo and scan it.
CatalogGET /public/scan-catalogPaginated, filterable catalog of all scans (by surface, severity, score).
OG pageGET /check/{owner}/{repo}Shareable HTML report page with Open Graph meta.

Verification & attestations

EndpointPathDescription
JWKSGET /.well-known/jwks.jsonPublic keys (EdDSA/Ed25519) for offline attestation verification. Served on agentgraph.co.
Attestations/attestationsIssue, list, and revoke signed attestations for an entity.
Security attestationGET /entities/{id}/attestation/securitySigned security-posture attestation (A2A trust.signals[] compatible).
Composed slotGET /entities/{id}/attestation/composed-slotagentgraph-scan-v1-structural slot for an APS composed-v1 envelope.
Aggregate verifyGET /trust/aggregate/{subject_did}/verifyVerify a signed Trust Score v2 aggregate envelope.

Account (authenticated)

EndpointPathDescription
Auth/authRegister, login, JWT tokens, email verification
Claims/account/claimsClaim a public repo you own via GitHub-topic proof (no token stored)
Private scanPOST /account/private-scanScan a private repo with a transiently-supplied GitHub token (never persisted)
Watches/watchesCreate/list/delete tool watches for grade + signed-definition change alerts
Alert webhook/account/alert-webhookConfigure (and test) the HMAC-signed webhook that receives change alerts
HealthGET /healthDB + Redis connectivity check

Project Structure

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Agentforge Trust MCP logoAgentforge Trust MCP

    Query the AgentForge Trust Score (0-100 across five dimensions: security, code health, behavioral audit, community trust, EU compliance) for any MCP server before connecting. Exposes checktrust, evaluatepolicy, listtrusted, and recommend tools. 3,600+ servers audited, free public API.

    ๐Ÿ”’ Security2 views
    Compare vs Agentforge Trust MCP โ†’
  • Agntor MCP logoAgntor MCP

    MCP audit server for agent discovery and certification. Provides trust and payment rail for AI agents including identity verification, escrow, settlement, and reputation management.

    ๐Ÿ”’ Security3 views
    Compare vs Agntor MCP โ†’
  • Agentradar MCP logoAgentradar MCP

    On-chain trust oracle for the ERC-8004 + x402 agent economy. 18 tools for verifying AI agents: 6-signal composite trust scoring (0-100), 272-wallet scam database, ERC-8004 identity lookup, EAS attestations on Base mainnet. x402-payable. Free getscore / checkscam. Live at vvpro.ai ยท npm @agentradar/mcp.

    ๐Ÿ”’ Security3 views
    Compare vs Agentradar MCP โ†’
  • Mobb Vibe Shield MCP logoMobb Vibe Shield MCP

    Mobb Vibe Shield identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

    ๐Ÿ”’ Security2 views
    Compare vs Mobb Vibe Shield MCP โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

GitHub stars
4
Stargazers on the source repository.
npm downloads
11
Package downloads in the last 30 days.
Last commit
3d ago
Most recent push to the default branch.
Availability
100%
Our rolling endpoint + install checks that succeeded.
Install check
Passed
Our sandbox started it and listed its tools.
Tools exposed
10
Callable tools this server registers over MCP.
Directory activity
2 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Agentgraph

No, the public scanning API requires no authentication.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewAgentgraph AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/agentgraph-co-agentgraph?style=directory)](https://allmcps.com/mcp/agentgraph-co-agentgraph)
HTML Embed
<a href="https://allmcps.com/mcp/agentgraph-co-agentgraph"><img src="https://allmcps.com/api/badge/agentgraph-co-agentgraph?style=directory" alt="Agentgraph on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
PricingFree
More technical detailsExpand โ–พ
TransportSTDIO
RuntimePython
AuthNo auth required
Last updatedSep 8, 2026
10/10 checks healthy over the last 33d
Views2
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars4
GitHub Star CountTotal stargazers on GitHub representing community popularity (4 stars).
Last commit3d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 8, 2026
npm downloads11/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
71Quality signal: Great ยท 71/100How this signal is calculated โ–พ
Server availability25/25
Verified ownership10/20
Documentation & tools30/30
Adoption & activity6/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 24d ago via OSV.dev ยท agentgraph-trust (PyPI)

โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to Agentgraph โ†’Install in Claude DesktopInstall in CursorInstall in VS Code