MCP-Vetting
mcp-vet
A trust-scan framework for MCP servers: evidence-backed verdicts before you install — usable from any harness.
uvx --from mcp-vetting mcp-vet @modelcontextprotocol/server-fetch # one command
uvx --from mcp-vetting mcp-vet ./my-server --harness hermes # verdict + config for YOUR harness
uvx --from mcp-vetting mcp-vet pypi:fastmcp --json --gate # machine-readable, CI-friendlyVerdicts: SAFE_TO_INSTALL · REVIEW_BEFORE_INSTALL · DO_NOT_INSTALL — every finding carries file:line and plain-English evidence. A verdict is a gate for humans, never a black box.
The flow
Vet any target: npm / PyPI / GitHub / local directory.
Read the verdict + findings (evidence, not vibes).
Configure: pick your harness, paste the emitted config block.
Gate it in CI with
--gate(exit 1 on DO_NOT_INSTALL).
Related MCP server: tooltrust-mcp
Three surfaces, one engine
Surface | Use |
Library |
|
CLI |
|
MCP server |
|
Targets
npm:pkg npm registry + tarball (bare names default to npm)
pypi:pkg PyPI JSON + sdist/wheel
gh:owner/repo GitHub metadata + source
./path local source directory (offline)
Bare names that fail to resolve on npm (e.g. PyPI-only servers like
`mcp-server-time`) automatically fall back to PyPI before reporting failure.Harness adapters (any harness, paste-ready)
--harness emits the exact config block for your tool:
harness | output |
| universal |
|
|
|
|
|
|
|
|
--harness all prints every adapter. Programmatic: config_for(harness, ServerSpec(...)).
Policy (calibrated defaults, --strict to disable)
Static analysis must not cry wolf. Defaults, learned by vetting the real ecosystem:
Examples/tests/docs are informational —
examples/,tests/,docs/code can't block a package on its own (strict restores raw findings).Fake secrets don't count —
sk-test-…,example,xxxxliterals are placeholders, not exfiltration.Trusted-host auth is normal — credentials sent to a host named in the file (constant or literal) is client auth; HIGH only when the destination host appears nowhere in the code.
Host interpolation → REVIEW —
https://${host}/…is a strong signal, but static analysis can't prove the host is user-controlled; a human decides. Strict mode blocks on it.
JSON schema (stable)
{
"target": "npm:some-server", "kind": "npm", "version": "1.2.3",
"verdict": {
"level": "REVIEW_BEFORE_INSTALL",
"summary": "3 finding(s); 0 high, 1 medium.",
"findings": [
{"scanner": "ssrf", "severity": "medium", "message": "...",
"file": "dist/index.js", "line": 41, "evidence": "fetch(url)"}
]
},
"provenance": {"version": "1.2.3", "license": "MIT",
"source_url": "git+https://...", "source": "npm"},
"files_scanned": 214, "duration_s": 1.7
}Scanners
ssrf · exec · secrets · auth · provenance · deps — static,
local-first (no telemetry, no cloud round-trips; the cache is a local SQLite
file under ~/.cache/mcp-vet).
Verification
python3 -m unittest discover -s tests # 48 checks: golden corpus is the quality barThe golden corpus is the contract: known-good fixtures must never carry HIGH
findings; malicious fixtures must always block. The ecosystem scan
(scripts/ecosystem_scan.py) keeps the tool honest against real packages.
Honest limits
Static analysis has false positives and negatives. A verdict is a gate for humans, not a replacement for them — read the evidence. Sandboxed execution, egress audit-trail, and live CVE lookups are planned for v2.
Maintenance
Related MCP Servers
- AlicenseAqualityCmaintenanceMCP server for https://oathe.ai security audits. Runtime behavioral analysis and security scanner for Ai systems. Check trust scores before installing MCP servers, plugins, or AI agent skills.5201MIT
- AlicenseNot gradedqualityAmaintenanceScans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.19MIT
- AlicenseAqualityCmaintenancePre-install trust scoring & safety scanning for MCP servers, AI skills & npm packages — 15 signals incl. OSV/KEV/EPSS vuln intel and an auto-gate go/no-go.91331MIT
- AlicenseAqualityAmaintenanceSecurity scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.55625MIT
Related MCP Connectors
Look up independent trust ratings and security, maintenance, and adoption evidence for MCP servers.
Independent A-F trust grade for any MCP server, watched for drift. Free, never for sale.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ElDiegolar/mcp-vet'
If you have feedback or need assistance with the MCP directory API, please join our Discord server