The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the MCP Shield listing page.
Reference implementations showing how to make AI agents check CraftedTrust before connecting to any MCP server. If a server scores D or F, the agent refuses to connect.
This is the "SSL certificate check for AI agents" pattern.
Add CraftedTrust to your agent's MCP config:
Your agent now has access to 6 tools:
| Tool | Description |
|---|---|
check_trust | Look up trust score by URL or npm name |
scan_server | Trigger a live security scan |
search_registry | Search 4,200+ indexed MCP servers |
get_stats | Ecosystem statistics |
pay_for_certification | Initiate USDC certification payment |
verify_payment | Verify on-chain payment |
Before your agent connects to any new MCP server:
check_trust on CraftedTrustSee python/trust_gated_agent.py for a complete LangGraph agent that gates MCP connections through CraftedTrust.
See typescript/trust-gated-client.ts for a TypeScript MCP client that checks trust scores before connecting.
| Grade | Score | Meaning |
|---|---|---|
| A | 90-100 | Excellent security practices |
| B | 75-89 | Good security, minor improvements possible |
| C | 60-74 | Adequate but has gaps |
| D | 40-59 | Significant security issues |
| F | 0-39 | Critical issues, do not connect |
Full API documentation: mcp.craftedtrust.com/api-docs.html
MIT
Built by Cyber Craft Solutions LLC