Trust scores for MCP servers

Know the server. Before you connect.

Paste a URL. Get a public trust report. Read-only, no credentials.

Read-only probe. We call initialize and tools/list only — never tools/call, and we never send credentials.

  1. 1. Connect over the MCP transport
  2. 2. List advertised tools
  3. 3. Score risk from the surface
  4. 4. Publish a shareable report
How it works

Three steps. Seconds.

01

Connect

One read-only MCP handshake. Initialize, then close.

02

List

Read every advertised tool — name, schema, description.

03

Score

Letter grade and verdict, backed by named rules.

Safe by construction

What we promise.

  • Never invokes a tool
  • Never sends credentials
  • Bounded: 10s, 1 MB
  • Public, shareable URL
Honest limits

A clean report doesn’t prove safety at runtime. We see what a server advertises, not what it does once invoked. Read the limits →