litmus
Server Details
Grade MCP servers A to F with the open behavioral litmus. npm: full toolset; hosted: lookups only.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Repository
- polygraphso/litmus
- GitHub Stars
- 8
- Server Listing
- Polygraph
TDQS
Scored across 3 tools
Each tool has a distinct purpose: check_server queries a single server's grade, list_servers lists graded servers, and request_grade is a discontinued stub that clearly informs the user. There is no overlap or ambiguity between them.
All three tools follow a consistent verb_noun pattern (check_server, list_servers, request_grade), making the API predictable and easy to reason about.
With exactly three tools, the server is well-scoped for a read-only grading service. Each tool earns its place, and the count is neither too sparse nor bloated.
The domain is querying published server grades, and the set covers checking individual servers, listing all graded servers, and gracefully handling the discontinued request path. No essential operations are missing for the intended use case.
Available Tools
3 toolscheck_serverCheck a server's published polygraph gradeARead-onlyInspect
Read a server's published behavioral grade (A-F) from polygraph.so in under a second; no execution. The pre-flight check before recommending or installing an MCP server. On a miss it returns not_available (unevaluated: neither safe nor unsafe) with next steps.
| Name | Required | Description | Default |
|---|---|---|---|
| server_ref | Yes | Registry-prefixed server ref: npm/<name>, npm/@scope/<name>, pypi/<name>, or github/<owner>/<repo>, with an optional @version. Example: npm/@modelcontextprotocol/server-filesystem |
Output Schema
| Name | Required | Description |
|---|---|---|
| grade | No | A-F, present when status is graded. |
| status | Yes | Whether a published grade exists. |
| categories | No | Per-category pass/fail, present when graded. |
| report_url | No | |
| self_grade | No | One-command reproduce/grade, present on a miss. |
| server_ref | Yes | |
| version_match | No | |
| current_version | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint and openWorldHint. The description adds concrete behavioral details: 'no execution', 'under a second', and the exact miss response format ('not_available: unevaluated'). This goes beyond the annotation hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three concise sentences with no filler. The first sentence delivers the core purpose; second gives usage context; third explains edge-case behavior. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the simple single-parameter schema, presence of output schema, and annotations, the description fully covers purpose, usage, and behavior. It is complete for an agent to select and invoke correctly without further clarification.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with a clear description and example for server_ref. The tool description does not add additional parameter semantics beyond what the schema provides. Baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it reads a server's published behavioral grade from polygraph.so, with a specific verb ('Read') and resource ('server's grade'). It distinguishes from siblings by positioning itself as a pre-flight check before installing an MCP server, contrasting with list_servers or request_grade.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says 'pre-flight check before recommending or installing an MCP server', indicating when to use. It also describes the miss behavior and return value ('not_available with next steps'), but does not explicitly define when not to use or name alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_serversList servers with a published gradeARead-onlyInspect
Servers with a published polygraph grade, sorted A-first then by ref. Returns up to limit rows starting at offset (default limit 25, capped at 100 per call); grade restricts to one letter. summary always covers the full graded corpus (a total plus a count per grade), regardless of grade, limit, or offset.
| Name | Required | Description | Default |
|---|---|---|---|
| grade | No | Restrict to servers with this grade. | |
| limit | No | Rows to return. Default 25, capped at 100 per call. | |
| offset | No | Rows to skip before taking `limit`, for paging past the first page. |
Output Schema
| Name | Required | Description |
|---|---|---|
| total | Yes | Rows matching `grade` (if given), before `limit`/`offset`. Equals summary.total when grade is omitted. |
| servers | Yes | |
| summary | Yes | Always covers the full graded corpus, independent of `grade`, `limit`, or `offset`. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations indicate readOnlyHint=true and openWorldHint=true. The description adds behavioral details beyond annotations: 'summary always covers the full graded corpus... regardless of grade, limit, or offset', which informs agents about side-effects and data scoping. No contradictions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with the tool's purpose and sorting. Every sentence provides essential behavioral or parameter context without redundancy. Efficient and clear.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given parameter count (3), full schema coverage, and existing output schema (not shown but noted), the description covers pagination logic, grade filtering, and summary behavior. No missing context needed for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Input schema covers parameters completely (100% coverage). The description adds value by explaining behavior: 'default limit 25, capped at 100 per call', 'grade restricts to one letter', and the special summary behavior. This goes beyond parameter descriptions in the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool returns 'Servers with a published polygraph grade, sorted A-first then by ref', specifying the verb (list), resource (servers), and sorting. It distinguishes from siblings check_server and request_grade which focus on individual servers or requesting grades.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explains behavior (pagination, grade filter, summary) but does not explicitly state when to use this tool versus its siblings (e.g., when you need a full list vs. checking a single server). Usage context is implied but alternatives are not mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
request_gradeRequest a polygraph grade for an MCP serverAIdempotentInspect
Hosted grading is discontinued. This tool returns gone. Existing published grades remain available via check_server / list_servers. To grade a server yourself, run the open harness: npx -y -p @polygraphso/litmus polygraphso-litmus litmus .
| Name | Required | Description | Default |
|---|---|---|---|
| server_ref | Yes | Registry-prefixed server ref: npm/<name>, npm/@scope/<name>, pypi/<name>, or github/<owner>/<repo>, with an optional @version. Example: npm/@modelcontextprotocol/server-filesystem |
Output Schema
| Name | Required | Description |
|---|---|---|
| demand | Yes | How many times this server has been requested. |
| status | Yes | |
| created | Yes | false if the server was already recorded. |
| payment | Yes | How grading is paid for. The web checkout settles up front in $POLYGRAPH; the x402 rail takes an authorization that is charged only once a grade lands, and a run the harness cannot complete voids it, so nothing is charged. The fee buys the run, never the grade. |
| requestId | Yes | The recorded request's id. |
| statusUrl | Yes | Poll for grading progress (unpaid, grading, graded, failed); check_server also reflects the published result. |
| server_ref | Yes | The server ref that was recorded. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses the key behavioral trait: the tool returns 'gone' and is effectively a stub. It also explains the reason (discontinued hosted grading) and where to find alternatives. Annotations already cover readOnly/destructive hints, but the description adds the context of the tool's non-functional status, which is valuable beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, front-loaded with the critical fact (hosted grading discontinued, returns gone), followed by alternatives and the self-harness command. Every sentence earns its place; no fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description is complete for an agent: it explains the tool's status, where to get existing grades, and how to self-grade. Since an output schema exists, return format is not required. There are no missing pieces for correct usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema covers the single parameter server_ref with a full description (100% coverage). The tool description does not add new semantic detail about the parameter itself; it only mentions it in the command example as a placeholder. The baseline 3 applies because the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: it returns 'gone' because hosted grading is discontinued. This is a specific, unambiguous behavior that distinguishes it from the sibling tools check_server and list_servers, which provide existing grades. The verb 'returns' and the resource 'gone' are explicit.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly tells the agent when NOT to use this tool (hosted grading is discontinued) and provides direct alternatives: use check_server/list_servers for existing grades, or run the open harness command for self-grading. This is clear, actionable guidance with no ambiguity.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
- First observed
check_server - First observed
list_servers - First observed
request_grade
Related MCP Connectors
Independent A-F trust grade for any MCP server, watched for drift. Free, never for sale.
Conformance checker for MCP servers. Free, no key, verdicts recomputable and re-measured daily.
Scores any MCP server before you trust it: free quick check, full paid report, 2-5 way compare.
Independent trust scores, tool surfaces and change history for MCP servers.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceEvaluates MCP servers by running read-only checks and returning a graded report with an A-F letter grade.1MIT

MCP Queen Registryofficial
AlicenseAqualityBmaintenanceCrawls and grades MCP servers deterministically, providing a registry, leaderboard, and API to query server grades and submit feedback.7MIT- AlicenseNot gradedqualityAmaintenancenpm audit for MCP servers. Point it at an MCP server and get a security grade (A–F) covering missing auth, SSRF surface, high-privilege tools, prompt-injection-prone tool descriptions, and leaked secrets.17 npmMIT
- AlicenseAqualityAmaintenanceAgent-readiness scorecard for any MCP server: protocol checks, 0-100 score and actionable findings.1152 npmMIT
Glama MCP Gateway
Add one secure layer between your agents and this server.