Skip to main content
Glama
YottaMeta

yotta-verify-mcp

Official
by YottaMeta

What it is

The skill / plugin market has a trust problem: a 2025 survey of 22,511 skills found 140,963 issues, and 36% contain prompt injection. 元信 MCP gives you a deterministic answer before you install — the same scan as the yotta-verify CLI, exposed as four MCP tools so any MCP client (Claude, VS Code, Codex, Cursor, …) can call it.

It is a pre-install verifier, not a sandbox and not a runtime monitor: it only reads files and prints a report. It never executes the scanned code, never connects to the network for the scan, and never fixes anything.

Related MCP server: MCP Shield

Why use it

Advantage

Description

Trust before install

A deterministic verdict for any skill / MCP server, instead of "trust me"

Zero dependency

Python 3.8+ standard library; no daemon / database / network

Fully local offline

Scans directories and npm tarballs on disk; nothing is executed or uploaded

Drop into any MCP client

Standard stdio MCP server — configure the server, and the four tools appear

Family synergy

Same rules table as yotta-verify (single source); verdicts merge with yotta-vetter / yotta-security-audit

Free & open

MIT; the whole scanner is free

MCP tools

Tool

What it does

scan_skill

Pre-install scan: target (dir / .tgz / npm package) → verdict + severity counts + findings

generate_badge

Audited badge: local SVG + shields.io URL; folds in validate / vetter / audit / version / tests

gate_check

CI gate: fail when the worst severity exceeds max_severity (default medium)

get_report

Verification report: Markdown or JSON, same format as the CLI

MCP client configuration

You usually do not need to write the mcpServers entry yourself: after installing this skill, an AI agent auto-adds the yotta-verify-mcp entry per the「AI 自动接入」section in SKILL.md, and falls back to the CLI scanner when MCP tools are unavailable.

Tool reference

scan_skill

Scan a skill directory or package before install.

Param

Type

Required

Meaning

target

string

yes

Skill directory path, .tgz / .tar.gz path, or npm package name (auto npm pack to a temp dir, then scan)

Returns a JSON result: verdict, severity counts, and findings (prompt injection / malicious patterns / SKILL.md integrity).

generate_badge

Generate an audited badge (local SVG + shields.io URL).

Param

Type

Meaning

target

string

Optional: scan this to derive the verdict

verdict

string

Optional: set the verdict directly

validate

string

Optional: pass / fail (validate-skill result)

vetter / audit

string

Optional: external verdicts to fold in

version

string

Optional: version label. Defaults to the scanner (yotta-verify) version (e.g. 0.1.1)

tests

integer

Optional: engine test count

out

string

Optional: write the SVG to this path

Note: the badge's version segment reflects the version of the scanning engine (yotta-verify), not the MCP package (0.1.4). Pass version to override.

gate_check

CI pre-install gate.

Param

Type

Meaning

target

string

Required: dir / package to scan

max_severity

string

Optional: info / low / medium / high / critical (default medium)

Returns pass, verdict, worst, max_severity and an exit code.

get_report

Generate a verification report.

Param

Type

Meaning

target

string

Required: dir / package to scan

format

string

Optional: json / markdown (default markdown)

out

string

Optional: write the report to this path

Boundary

This is a local, offline, static scan:

  • Directory scan is fully offline — content never leaves your machine.

  • npm package scan only downloads the public package into a temporary directory (then removes it); it does not upload your content and does not execute the scanned package code.

  • It does not perform dynamic analysis, does not fix anything, and does not make the final decision. Treat the verdict as a strong signal and confirm any "install / don't install" decision yourself.

  • Only scan targets you are authorised to evaluate.

Installation of the skill

The package also ships a SKILL.md so an agent can learn how to configure and use the MCP server. Pick any of the four methods below (skill files come from npm; GitHub can be slow without a proxy).

# Optional China mirror: npm config set registry https://registry.npmmirror.com
npx -y @yottameta/yotta-verify-mcp --agent <agent-name>      # install to the agent's default user-level skills dir
npx -y @yottameta/yotta-verify-mcp --dir <your-skills-dir>   # point to the skills dir itself (e.g. ~/.codex/skills)
  • --agent <name> installs to that agent's default user-level directory; --list shows each agent's default directory.

  • --dir <path> installs to the given directory.

  • The installer also starts an MCP server when run with no arguments: npx -y @yottameta/yotta-verify-mcp.

Method 2: git clone (developers / git available)

git clone https://github.com/YottaMeta/yotta-verify-mcp.git <your-skills-dir>/yotta-verify-mcp

Method 3: GitHub Download ZIP (manual / no git)

On the GitHub repository YottaMeta/yotta-verify-mcp, click Code → Download ZIP, unzip it and put the yotta-verify-mcp folder into the agent's skills directory.

Method 4: install.sh (multi-agent one-liner script)

bash install.sh --agent <name>   # install to the agent's default user-level directory
bash install.sh --dir <path>     # install to the given directory
bash install.sh --list           # list agents -> default directories

Development & validation

The package ships its own test suite (included in the published package):

# Run the full suite (32 cases) from the skill directory (Python 3.8 / 3.13 both green)
python scripts/test_yotta_verify_mcp.py

# Run the MCP server directly for debugging
python scripts/yotta_verify_mcp.py

References: references/trust-checklist.md (pre-install trust checklist for MCP servers / plugins).

License

MIT © YottaMeta — see LICENSE.

Maintenance

ActivityMaintained
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    B
    maintenance
    Static security scanner for AI agent skill packages that detects malicious SKILL.md files and bundled scripts before they run.
    15
  • A
    license
    C
    quality
    B
    maintenance
    Security scanner and MCP server that catches dangerous patterns in MCP servers and AI agent projects, such as leaked secrets, shell execution, and prompt-injection text. Runs as both a CLI and MCP server with CI-friendly severity gates.
    2
    1
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Audits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.
    2
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    Security scanner for third-party AI agent-skill files: SKILL.md manifests, hooks, and bundled scripts, exposed via an MCP tool.
    1
    23
    1
    Apache 2.0

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/YottaMeta/yotta-verify-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server