Check the danger grade of any public MCP server before you connect.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Check before you connect. A neutral, public danger grade for the MCP servers your AI agents rely on.
Live: mcp-trust.vercel.app
Not yet published to PyPI. Install from source using the Quickstart below.
mcp-trust runs as a read-only MCP server so an agent can check a server's
danger grade before connecting β it serves a baked snapshot of real scan
grades with explicit per-record provenance, so no database or network is needed.
| Tool | Description |
|---|---|
list_servers | Every graded MCP server with its A-F grade, transparency, and danger score. |
check_server | Full grade, risk dimensions, and findings for one server by slug. |
get_methodology | How the A-F grade and transparency axis are computed, plus the honesty model. |
The MCP runtime admits the packaged catalog only after deterministic schema-v2 validation, including duplicate-key rejection, required field/type checks, unique slugs and source coordinates, supported enums, sandbox/scan-mode agreement, and timezone-aware scan timestamps. Admission also binds grade to danger score, transparency to annotation coverage, and critical findings to the grade cap. Raw JSON is limited to 1 MiB, with deterministic server, finding, tool, and public-string ceilings. Schema v2 preserves additive unknown fields; missing or invalid required fields and unknown schema versions fail closed.
If catalog admission fails, list_servers and check_server serve zero records
and return mcp-trust-mcp-error.v1 with status UNKNOWN, error code
CATALOG_SNAPSHOT_INVALID, sorted reason codes, and server_count_served: 0.
get_methodology remains available. This boundary checks internal consistency;
it does not prove snapshot authenticity, authorship, immutability, or freshness.
Offline consumers can add those missing publication checks with
mcp-trust verify-snapshot: a detached Ed25519 statement binds the exact
snapshot bytes, publisher ID, bounded issue/expiry window, monotonic publication
ID, and prior consumer checkpoint. The consumer must independently pin the
trust-root SHA-256 and preserve the returned checkpoint for rollback resistance.
Invalid, expired, unknown-signer, forked, or rolled-back inputs return only
UNKNOWN reason codes and no grades. See
docs/OFFLINE-SNAPSHOT-TRUST-V1.md.
Statement freshness proves recent publication authorization, not a recent scan;
the per-record scan timestamp and 90-day stale policy remain separate checks.
No production trust root, signing key, statement, or checkpoint ships today, so the built-in MCP snapshot remains structural-only unless a consumer separately supplies and pins those inputs. Test fixture keys are not publication keys.
Connecting an MCP server hands it influence over what your agent does. Tool poisoning, prompt injection, over-broad permissions, and rug-pull tool mutations are documented attack classes -- and today there's no quick way to vet a server before you wire it in. MCP Trust Registry scans public MCP servers and gives each one a single readable danger grade (A-F), a separate transparency signal, and the findings behind them.
Think OSV.dev / Socket.dev / haveibeenpwned, scoped to MCP servers.
uv (used for dependency management and running the project)Render one versioned, secret-placeholder-only MCP connection intent into staged Codex, Claude Code, Claude Desktop, or VS Code configuration and receive an explicit semantic loss/widening report:
The studio is local-only. It never discovers or edits a real host config,
launches an MCP server, contacts a URL, or emits modeled secret values. Generated
configuration proves only documented host-format compatibility, not a runtime
connection or adoption. See
docs/MCP-CONFIG-PORTABILITY-STUDIO.md.
The registry does not reimplement vulnerability detection. It orchestrates a
pluggable scan engine -- the shipping backend wraps the public
mcp-audits (>=2.1) package -- and owns the
catalog, the public trust-grade normalization, persistence, and the lookup API.
For real scanning install the engine extra and select it:
Scanning launches the server's process. For untrusted servers, isolate execution in a locked-down container (no network, read-only fs, dropped caps, resource limits):
The default is no sandbox (safe only for servers you trust).
| Method | Path | Purpose |
|---|---|---|
GET | / | web -- public catalog page (grade + transparency per server) |
GET | /ui/servers/{slug} | web -- server detail page + README badge-embed snippet |
GET | /healthz | liveness |
GET | /servers | catalog + latest grade, provenance, and staleness per server (JSON) |
GET | /servers/{slug} | full latest scan record + provenance/staleness and metadata (JSON) |
POST | /servers/{slug}/scan | operator scan trigger; public deployments disable this route |
GET | /servers/{slug}/badge.json | shields.io-compatible README badge |
Every server has two orthogonal signals: a danger grade (A-F) and a transparency level (high/medium/low, from annotation coverage). Automated grades are not endorsements, certifications, or claims that a server is malicious. A low grade on a low-transparency server means "cannot verify safe," not "known dangerous."
HTTP scan triggering is fail-closed by default. Public deployments should set
MCP_TRUST_PUBLIC_READONLY=1, which makes POST /servers/{slug}/scan return
403 before any engine can run. Operator scans should normally run through the
CLI against the persistent registry DB, not through public traffic.
For local API demos with the deterministic StubEngine, set
MCP_TRUST_ALLOW_UNAUTHENTICATED_STUB_SCANS=1. Do not set that in public.
Token-gated API scan triggering is still available for private operator surfaces
by setting MCP_TRUST_SCAN_TOKEN and passing it as Authorization: Bearer <token> or X-MCP-Trust-Scan-Token.
If the newest stored scan row is unreadable, API, web, static, badge, and
snapshot projections fail closed to UNKNOWN; they never resurrect an older
grade. Stored source/risk/finding/evidence JSON has a 1 MiB per-field admission
ceiling, with bounded finding/tool collections and content-free diagnostics.
An unreadable older row leaves a readable latest grade intact but makes scan
history and grade-change claims explicitly UNKNOWN. Snapshot construction
stops until unreadable history is repaired or dispositioned.
All public surfaces use one fail-closed freshness projection. Exactly 90 days
after a scan is still FRESH; any later instant is STALE. Missing, malformed,
or future scan times are UNKNOWN, with verdict fields withheld. Unscanned
entries are NOT_APPLICABLE. Operator masking applies even when no scan exists
and is never inferred from scan state. Static pages and badges are immutable
historical evidence with a scan date or validity boundary; they do not promise
request-time freshness. Danger, transparency, and evidence quality remain
separate signals, and a grade is never an endorsement.
Set MCP_TRUST_RECEIPTS_DIR=/data/mcp-trust/receipts during real scan runs to
archive a JSON receipt for each scan and store its portable artifact filename in
report_ref.
Remote Registry candidates can be checked for discoverable MCP authorization
metadata without contacting the MCP endpoint or handling credentials. First
build a candidate manifest from a previously saved official Registry response,
then select one exact stable_id:
If a public WWW-Authenticate: Bearer challenge has already been obtained by a
separate operator workflow, pass its value with --www-authenticate. Otherwise
the command tries the MCP-required protected-resource well-known paths, followed
by RFC 8414 and OpenID Connect authorization-server discovery in specification
order.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-trust)<a href="https://allmcps.com/mcp/mcp-trust"><img src="https://allmcps.com/api/badge/mcp-trust?style=directory" alt="MCP Trust on AllMCPs" /></a>