Skip to main content
Glama

Server Details

Signed security scores for what an AI agent runs and reads: skills, MCP servers, prompts, tokens.

If you are the author of this connector, you can claim ownership with GitHub, an HTTP challenge, or a DNS record. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Unhealthy
Last Tested
Transport
Streamable HTTP
URL

TDQS

A4/5.0

Scored across 13 tools

Disambiguation5/5

Each tool has a clearly distinct purpose, from identity lookup and posture scoring to specific scans for skills, MCP servers, and user input. No two tools appear to overlap in function, and descriptions are detailed enough to avoid confusion.

Naming Consistency4/5

All tools use the 'heron_' prefix and underscores, with a mix of noun phrases (e.g., heron_agent_identity) and verb imperatives (e.g., heron_inspect). The pattern is mostly consistent, though the mix of noun and verb forms is a minor deviation.

Tool Count5/5

With 13 tools, the set is well-scoped for a security analysis service. Each tool covers a specific aspect of agent and server safety, leaving no apparent bloat or scarcity.

Completeness4/5

The tools cover core security workflows: identity, posture, red-teaming, input inspection, and verification. The inclusion of heron_score (URL citability) is slightly tangential but not a major gap. Minor missing features like batch scanning or historical comparisons prevent a perfect score.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool update
    • Changedheron_inspect1 field changed
      • changedInput schema / properties / deep / default
        Previous value: -falseNew value: +true
  2. 1 tool update
    • Addedheron_token_scan
  3. 2 tool updates
    • Addedheron_agent_posture
    • Addedheron_inspect
  4. 11 tool updates
    • First observedheron_agent_identity
    • First observedheron_agent_redteam
    • First observedheron_full_report
    • First observedheron_manifest
    • First observedheron_mcp_scan
    • First observedheron_methodology
    • First observedheron_negotiate
    • First observedheron_score
    • First observedheron_skill_scan
    • First observedheron_trust_index
    • First observedheron_verify_attestation

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    Security scanning for AI agent skills, MCP servers, and agent prompts, returning signed trust scores and detailed findings.
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    On-chain trust verification for AI agent tools. Agents query skill attestations, audit levels, and risk scores before running third-party MCP servers, so you know what's safe before you execute.
    1
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    Audits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.
    2
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    Security co-pilot for AI agents. Scans for vulnerabilities like prompt injection, infinite loops, and token bombing in AI Agents, audits MCP servers, verifies AGENTS.md governance, and generates EU AI Act compliance reports.
    10
    28
    3
    Apache 2.0
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources