MCP-Vetting
mcp-vet
A trust-scan framework for MCP servers: evidence-backed verdicts before you install — usable from any harness.
uvx --from mcp-vetting mcp-vet @modelcontextprotocol/server-fetch # one command
uvx --from mcp-vetting mcp-vet ./my-server --harness hermes # verdict + config for YOUR harness
uvx --from mcp-vetting mcp-vet pypi:fastmcp --json --gate # machine-readable, CI-friendlyVerdicts: SAFE_TO_INSTALL · REVIEW_BEFORE_INSTALL · DO_NOT_INSTALL — every finding carries file:line and plain-English evidence. A verdict is a gate for humans, never a black box.
The flow
Vet any target: npm / PyPI / GitHub / local directory.
Read the verdict + findings (evidence, not vibes).
Configure: pick your harness, paste the emitted config block.
Gate it in CI with
--gate(exit 1 on DO_NOT_INSTALL).
Related MCP server: tooltrust-mcp
Three surfaces, one engine
Surface | Use |
Library |
|
CLI |
|
MCP server |
|
Targets
npm:pkg npm registry + tarball (bare names default to npm)
pypi:pkg PyPI JSON + sdist/wheel
gh:owner/repo GitHub metadata + source
./path local source directory (offline)Harness adapters (any harness, paste-ready)
--harness emits the exact config block for your tool:
harness | output |
| universal |
|
|
|
|
|
|
|
|
--harness all prints every adapter. Programmatic: config_for(harness, ServerSpec(...)).
Policy (calibrated defaults, --strict to disable)
Static analysis must not cry wolf. Defaults, learned by vetting the real ecosystem:
Examples/tests/docs are informational —
examples/,tests/,docs/code can't block a package on its own (strict restores raw findings).Fake secrets don't count —
sk-test-…,example,xxxxliterals are placeholders, not exfiltration.Trusted-host auth is normal — credentials sent to a host named in the file (constant or literal) is client auth; HIGH only when the destination host appears nowhere in the code.
Host interpolation → REVIEW —
https://${host}/…is a strong signal, but static analysis can't prove the host is user-controlled; a human decides. Strict mode blocks on it.
JSON schema (stable)
{
"target": "npm:some-server", "kind": "npm", "version": "1.2.3",
"verdict": {
"level": "REVIEW_BEFORE_INSTALL",
"summary": "3 finding(s); 0 high, 1 medium.",
"findings": [
{"scanner": "ssrf", "severity": "medium", "message": "...",
"file": "dist/index.js", "line": 41, "evidence": "fetch(url)"}
]
},
"provenance": {"version": "1.2.3", "license": "MIT",
"source_url": "git+https://...", "source": "npm"},
"files_scanned": 214, "duration_s": 1.7
}Scanners
ssrf · exec · secrets · auth · provenance · deps — static,
local-first (no telemetry, no cloud round-trips; the cache is a local SQLite
file under ~/.cache/mcp-vet).
Verification
python3 -m unittest discover -s tests # 48 checks: golden corpus is the quality barThe golden corpus is the contract: known-good fixtures must never carry HIGH
findings; malicious fixtures must always block. The ecosystem scan
(scripts/ecosystem_scan.py) keeps the tool honest against real packages.
Honest limits
Static analysis has false positives and negatives. A verdict is a gate for humans, not a replacement for them — read the evidence. Sandboxed execution, egress audit-trail, and live CVE lookups are planned for v2.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityCmaintenanceMCP server for https://oathe.ai security audits. Runtime behavioral analysis and security scanner for Ai systems. Check trust scores before installing MCP servers, plugins, or AI agent skills.Last updated5231MIT
- Alicense-qualityAmaintenanceScans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.Last updated19MIT
- AlicenseAqualityAmaintenancePre-install trust scoring & safety scanning for MCP servers, AI skills & npm packages — 15 signals incl. OSV/KEV/EPSS vuln intel and an auto-gate go/no-go.Last updated9651MIT
- AlicenseAqualityAmaintenanceSecurity scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.Last updated55165MIT
Related MCP Connectors
Independent A-F trust grade for any MCP server, watched for drift. Free, never for sale.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ElDiegolar/mcp-vet'
If you have feedback or need assistance with the MCP directory API, please join our Discord server