trust-oracle

Independent A-F trust grade for any MCP server, watched for drift. Free, never for sale.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
93%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~411Tokens (tool definitions)
~659 BTypical response size
Minimal attention impact (0.32% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "trust-oracle": {
      "url": "https://wmcp.sh/mcp/trust"
    }
  }
}

Remote endpoints

https://wmcp.sh/mcp/truststreamable-http

What it can do

Tool inventory

Tools (3)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪grade_mcp_server(url, fresh)

Independently grade an MCP server (A–F) BEFORE connecting an agent to it. Returns spec-conformance, security (OWASP MCP Top 10), reliability, tool-hygiene and transparency sub-scores plus a connect/caution/avoid recommendation. Audited by wmcp.sh; the grade is free and never for sale.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The MCP server endpoint URL to grade (e.g. https://mcp.example.com/mcp)."
    },
    "fresh": {
      "type": "boolean",
      "description": "Force a live re-probe instead of returning a recent cached grade."
    }
  },
  "required": [
    "url"
  ]
}
🟡check_mcp_drift(url)

Check whether an MCP server's tool definitions have changed since it was last trusted (rug-pull / schema-drift detection, the CVE-2025-54136 class). Returns how long the tool surface has been stable, how many times it has changed, and the last change. Use after approval to detect post-trust mutation.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The MCP server endpoint URL to check."
    }
  },
  "required": [
    "url"
  ]
}
🟢verify_before_execute(url, fresh)

Verify an MCP server immediately BEFORE you execute any of its tools. Combines the continuously-watched trust grade and live drift status into a single connect/caution/avoid verdict (ok | caution | drifted | failing | ungraded), so you can gate the call in one step. Free, read-tier. The grade is independent and never for sale.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The MCP server endpoint URL you are about to call."
    },
    "fresh": {
      "type": "boolean",
      "description": "Force a live re-probe instead of returning a recent cached grade (<6h)."
    }
  },
  "required": [
    "url"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded3 tools
verifiedversion not recorded3 tools
verifiedversion not recorded3 tools