Skip to main content
Glama

Related Servers

Alternatives to Polygraph

  • A
    license
    Not graded
    quality
    A
    maintenance
    An MCP server that enables easy integration with coding assistants, providing security context to AI agents. This runs locally using the Snyk CLI.
    55
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    Drop-in security primitives for MCP servers, addressing isError compliance, audit trails, input validation, output sanitization, and OAuth scoping.
    7
    MIT

Related Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    A transparent MCP proxy that independently re-verifies tool-call claims instead of trusting them, paired with devmcp — the git/CI server it's proven against.
    1
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A continuous, out-of-band trust and reliability layer for the MCP ecosystem. It fingerprints MCP server tool definitions, detects and classifies drift (e.g., rug pulls) via a severity taxonomy, maintains a hash-chained evidence ledger, and gates CI with SARIF—while also acting as an MCP server itself so agents can check a server's safety before binding.
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    Audits any MCP server (stdio or Streamable HTTP, legacy or modern era) with wire-level conformance, security, and behavior-regression checks, producing a fingerprinted delivery report and CI regression suite.
    1
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    A compact MCP server demonstrating explicit tool boundaries, least-privilege discovery, execution-time authorization, destructive-action confirmation, and metadata-only audit logs using a local note store.
    3
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    A governed MCP server exposing 37 risk-checked tools with signed Ed25519 receipts on a Bitcoin-anchored ledger, failing closed if governance or receipt writing fails.
    -

TDQS

A4.3/5.0

Scored across 2 tools

Disambiguation5/5

The two tools target distinctly different objects: one reads published attestations for servers, the other grades skills. Their descriptions clearly differentiate their purposes and use cases, leaving no ambiguity.

Naming Consistency4/5

Both tool names follow an underscore-separated verb_noun pattern, but the verbs differ (verify vs. run) and the nouns are not parallel (attestation vs. skill_litmus). Minor inconsistency, but overall predictable.

Tool Count3/5

With only 2 tools, the server is at the lower end of what is reasonable. While the scope is focused, the inclusion of a third tool (e.g., run_litmus for servers) would improve coverage without bloat.

Completeness2/5

The description of verify_attestation mentions a run_litmus tool for server grading that is not present, and there is no tool for publishing attestations. These gaps mean agents cannot perform the full workflow implied by the server's purpose.

Maintenance

ActivityStale
ResponsivenessResponsive