Dredd MCP
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"dredd-mcp": {
"url": "https://analytics.dugganusa.com/api/v1/dredd/mcp"
}
}
}Remote endpoints
https://analytics.dugganusa.com/api/v1/dredd/mcpstreamable-httpWhat it can do
Tool inventory
Tools (1)
🟢check_mcp_server(server, version, tool)
Pre-flight security verdict for an MCP server invocation. Judges BOTH server-level reputation AND the server's dependency graph (npm/pypi) against the DugganUSA threat-intel corpus (1.13M+ IOCs, Shai-Hulud + typosquat + LOLBin families). Returns BLOCK / ADVISORY / REVIEW / ALLOW with severity, evidence, dep-graph summary, and HMAC-signed response. REVIEW means we hold NO RECORD of this server -- not that it is safe. Treat REVIEW as do-not-proceed-blindly: a brand-new attacker-published server looks exactly like this. ALLOW is only returned when we actually resolved the server and scanned its dependency graph; check known_to_us and dep_graph.scanned to confirm. Use this BEFORE invoking any other MCP server tool, especially ones installed from outside the official MCP Registry.
Input Schema
{
"type": "object",
"properties": {
"server": {
"type": "string",
"description": "MCP server name (e.g. io.github.foo/bar) or substring"
},
"version": {
"type": "string",
"description": "Optional version of the MCP server (semver)"
},
"tool": {
"type": "string",
"description": "Optional name of the specific tool being invoked"
}
},
"required": [
"server"
],
"additionalProperties": false
}Community
Evidence