Skip to main content
Glama
nullbuilds-ai

null-trust-score

README.md
# null-trust-score

MCP server that exposes trust scores for MCP servers. Query before you connect.

Built by [NULL](https://nullbuilds.vercel.app) ([@nullbuilds](https://x.com/nullbuilds)).

## What it does

Any AI agent can query this MCP server to check whether an MCP server is safe to connect to. Returns a composite trust score (0-100), letter grade (A-F), per-dimension breakdown, and recommendation.

53 MCP servers scored. 3 with full security reviews (46 findings). 50 auto-scored from public signals.

## Tools

| Tool | Description |
|------|-------------|
| `trust_get_score` | Get trust score for a specific MCP server |
| `trust_search_servers` | Search servers by name, score, or grade |
| `trust_get_review` | Get full security review with findings |
| `trust_list_flagged` | List servers graded D or F |
| `trust_check_batch` | Check multiple servers at once (max 25) |

## Scoring

6 dimensions, weighted composite:

| Dimension | Weight | What it measures |
|-----------|--------|------------------|
| Security | 25% | Input validation, credential handling, sandboxing |
| Reliability | 20% | Error handling, graceful degradation, timeouts |
| Documentation | 15% | README quality, tool descriptions, examples |
| Maintenance | 20% | Commit recency, release cadence, dependency freshness |
| Design | 10% | Tool naming, response format, annotations |
| Ecosystem | 10% | Downloads, stars, directory listings |

Grades: A (80-100), B (60-79), C (40-59), D (20-39), F (0-19).

Servers with full reviews get scores across all 6 dimensions. Auto-scored servers (from public signals only) get a `scoring_version: "auto-1.0"` tag.

## Installation

```bash
npm install
npm run build
npm run seed   # populate trust.db with 53 servers
```

## Usage

### With Claude Code

Add to your `.mcp.json`:

```json
{
  "mcpServers": {
    "null-trust-score": {
      "command": "node",
      "args": ["/path/to/null-trust-score/dist/index.js"]
    }
  }
}
```

### With MCP Inspector

```bash
npm run inspect
```

## Data sources

- **Reviewed servers**: Full source code audit by NULL. Findings verified against actual code.
- **Discovery queue**: 50 top MCP servers ranked by downloads, stars, first-party status, and recency. Auto-scored using maintenance and ecosystem signals.

## License

MIT