trust-oracle
Independent A-F trust grade for any MCP server, watched for drift. Free, never for sale.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"trust-oracle": {
"url": "https://wmcp.sh/mcp/trust"
}
}
}Remote endpoints
https://wmcp.sh/mcp/truststreamable-httpWhat it can do
Tool inventory
Tools (3)
⚪grade_mcp_server(url, fresh)
Independently grade an MCP server (A–F) BEFORE connecting an agent to it. Returns spec-conformance, security (OWASP MCP Top 10), reliability, tool-hygiene and transparency sub-scores plus a connect/caution/avoid recommendation. Audited by wmcp.sh; the grade is free and never for sale.
Input Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The MCP server endpoint URL to grade (e.g. https://mcp.example.com/mcp)."
},
"fresh": {
"type": "boolean",
"description": "Force a live re-probe instead of returning a recent cached grade."
}
},
"required": [
"url"
]
}🟡check_mcp_drift(url)
Check whether an MCP server's tool definitions have changed since it was last trusted (rug-pull / schema-drift detection, the CVE-2025-54136 class). Returns how long the tool surface has been stable, how many times it has changed, and the last change. Use after approval to detect post-trust mutation.
Input Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The MCP server endpoint URL to check."
}
},
"required": [
"url"
]
}🟢verify_before_execute(url, fresh)
Verify an MCP server immediately BEFORE you execute any of its tools. Combines the continuously-watched trust grade and live drift status into a single connect/caution/avoid verdict (ok | caution | drifted | failing | ungraded), so you can gate the call in one step. Free, read-tier. The grade is independent and never for sale.
Input Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The MCP server endpoint URL you are about to call."
},
"fresh": {
"type": "boolean",
"description": "Force a live re-probe instead of returning a recent cached grade (<6h)."
}
},
"required": [
"url"
]
}Community
Evidence