registry

The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
98%
Qualität der Benennung
100%
Risiko der Vergiftung
80%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Befunde (2)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains URL to non-standard domainin get_change_events

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~818Tokens (Tool-Definitionen)
~905 BTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (0.64% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "registry": {
      "url": "https://api.policylayer.com/mcp"
    }
  }
}

Remote-Endpunkte

https://api.policylayer.com/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (5)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟢check_mcp_server(server)

Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk grade, auth posture, freshness, and the tool surface listed riskiest-first. A server the registry does not know is queued for scanning by this very call — check back shortly.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "server": {
      "type": "string",
      "description": "Registry slug, npm package name (e.g. @acme/mcp-server), remote URL, or server name."
    }
  },
  "required": [
    "server"
  ]
}
🟢check_mcp_stack(servers)

Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdict (attention signals and a suggested action) — and the lookup status for every miss; counts, grades and flagged tools come from the published records only. Costs one rate-limit unit per server.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "servers": {
      "type": "array",
      "maxItems": 25,
      "description": "One entry per server in the stack.",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "description": "Your label for this server (e.g. its config key) — echoed back on the result."
          },
          "candidates": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "maxItems": 5,
            "description": "Identifiers to try in order: npm package name, registry slug, or remote URL. Most package-like first."
          }
        },
        "required": [
          "candidates"
        ]
      }
    }
  },
  "required": [
    "servers"
  ]
}
🟢search_registry(query, limit)

Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand) and tool count — follow up with check_mcp_server on the match you meant.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Substring to match against slug, name and packages."
    },
    "limit": {
      "type": "number",
      "description": "Max matches to return (1-20, default 10)."
    }
  },
  "required": [
    "query"
  ]
}
🟢check_tool(server, tool)

One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. "should execute_sql on this server be permitted?"

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "server": {
      "type": "string",
      "description": "Registry slug or npm package name of the server."
    },
    "tool": {
      "type": "string",
      "description": "Tool name as the server declares it."
    }
  },
  "required": [
    "server",
    "tool"
  ]
}
🟡get_change_events(after_id, limit, severity)

The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at https://policylayer.com/registry/pricing.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "after_id": {
      "type": "number",
      "description": "Return events with id greater than this cursor (default 0)."
    },
    "limit": {
      "type": "number",
      "description": "Max events (1-1000, default 200)."
    },
    "severity": {
      "type": "string",
      "enum": [
        "info",
        "notice",
        "warning",
        "critical"
      ],
      "description": "Minimum severity: that level and above."
    }
  }
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet5 Tools
verifiziertVersion nicht aufgezeichnet5 Tools