VerifyMCP
Independent trust scores, tool surfaces and change history for MCP servers.
Should I use this
Quality & Safety
Findings (1)
- LOWin get_server_diagnostics
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"mcp": {
"url": "https://mcp.verifymcp.io"
}
}
}Remote endpoints
https://mcp.verifymcp.iostreamable-httpWhat it can do
Tool inventory
Tools (9)
🟢list_servers(query, product, types, minScore, maxScore, ...)
Filter the VerifyMCP directory of scored MCP servers. Use to discover servers by name fragment, ecosystem, product or trust score. Name matching only: descriptions and capabilities are not searched, so a plain-English question matches nothing. Returns the first 100.
Input Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"maxLength": 100,
"description": "Name fragment to match against server and package names."
},
"product": {
"type": "string",
"description": "Restrict to servers classified as working with this product, e.g. github."
},
"types": {
"type": "array",
"items": {
"type": "string",
"enum": [
"remote",
"npm",
"pypi",
"oci",
"nuget",
"mcpb"
]
},
"description": "Restrict to these ecosystems; a server matches any one of them."
},
"minScore": {
"type": "integer",
"minimum": 0,
"maximum": 100,
"description": "Lowest trust score to include."
},
"maxScore": {
"type": "integer",
"minimum": 0,
"maximum": 100,
"description": "Highest trust score to include."
},
"scored": {
"type": "string",
"enum": [
"scored",
"unscored",
"all"
],
"default": "scored",
"description": "Include unscored servers. Defaults to scored only."
},
"sort": {
"type": "string",
"enum": [
"score_desc",
"score_asc",
"name_asc",
"name_desc",
"channels_asc",
"channels_desc"
],
"description": "Default: best match (then trust) with a query, else trust. A given sort is applied exactly."
}
},
"additionalProperties": false,
"examples": [
{
"query": "github"
},
{
"product": "github",
"minScore": 70
},
{
"types": [
"remote"
],
"minScore": 80,
"sort": "score_desc"
},
{
"types": [
"npm",
"pypi"
],
"scored": "scored"
},
{
"query": "postgres",
"types": [
"npm"
]
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"slug",
"name",
"registryName",
"description",
"score",
"status",
"weekDelta",
"componentTypes",
"products",
"liveness",
"registryStatus",
"claimed",
"url"
],
"properties": {
"slug": {
"type": "string",
"description": "Stable verifymcp identifier for this server."
},
"name": {
"type": "string",
"description": "Human-readable display name."
},
"registryName": {
"type": "string",
"description": "Reverse-DNS registry name."
},
"description": {
"type": [
"string",
"null"
],
"description": "Publisher-supplied summary."
},
"score": {
"type": [
"integer",
"null"
],
"description": "Best trust score 0-100; null when unscored."
},
"status": {
"type": [
"string",
"null"
],
"description": "Scoring status for the best component."
},
"weekDelta": {
"type": [
"integer",
"null"
],
"description": "Score movement over the last 7 days."
},
"componentTypes": {
"type": "array",
"items": {
"type": "string"
},
"description": "Ecosystems this server ships in."
},
"products": {
"type": "array",
"items": {
"type": "string"
},
"description": "Product slugs this server is classified as working with. Empty means either classified to nothing or not yet classified; the two are indistinguishable."
},
"liveness": {
"type": "string",
"description": "Reachability: live, grace, degraded or dead."
},
"registryStatus": {
"type": "string",
"description": "Registry lifecycle: active, deprecated or deleted."
},
"claimed": {
"type": "boolean",
"description": "Owner has proved ownership of this listing."
},
"url": {
"type": "string",
"description": "Canonical verifymcp.io page for this server."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}🟢get_server(identifier, component)
Get the full VerifyMCP trust report for one MCP server: score with per-category verdicts and reasons, the tools it exposes with their context-token cost, and its recent change history. Use before installing or trusting a server. Accepts a package name, endpoint URL, registry name or verifymcp slug.
Input Schema
{
"type": "object",
"properties": {
"identifier": {
"type": "string",
"description": "Package name, endpoint URL, registry name or verifymcp slug."
},
"component": {
"type": "string",
"description": "Which channel to report on when a server ships several."
}
},
"required": [
"identifier"
],
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"identifier": "io.github.acme/tools",
"component": "npm"
},
{
"identifier": "acme-tools"
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"properties": {
"slug": {
"type": "string",
"description": "Stable verifymcp identifier."
},
"component": {
"type": "string",
"description": "Channel reported on."
},
"name": {
"type": "string",
"description": "Display name."
},
"registryName": {
"type": "string",
"description": "Reverse-DNS registry name."
},
"description": {
"type": [
"string",
"null"
],
"description": "Publisher summary."
},
"identifier": {
"type": "string",
"description": "Package name or endpoint URL of this channel."
},
"type": {
"type": "string",
"description": "Ecosystem: remote, npm, pypi, oci, nuget or mcpb."
},
"score": {
"type": [
"integer",
"null"
],
"description": "Trust score 0-100; null when never scored."
},
"status": {
"type": [
"string",
"null"
],
"description": "Scoring status."
},
"lastScoredAt": {
"type": [
"string",
"null"
],
"description": "When this channel was last scored."
},
"categories": {
"type": "array",
"description": "Per-category breakdown in rubric order.",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"score",
"verdict",
"reasons"
],
"properties": {
"name": {
"type": "string",
"description": "Category name."
},
"score": {
"type": [
"integer",
"null"
],
"description": "Category score; null when pending."
},
"verdict": {
"type": "string",
"enum": [
"pass",
"partial",
"fail",
"unverified"
],
"description": "unverified means we could not determine it, NOT that it failed."
},
"reasons": {
"type": "array",
"items": {
"type": "string"
},
"description": "Plain-English findings."
}
}
}
},
"inconclusive": {
"type": "array",
"items": {
"type": "string"
},
"description": "Checks we could not complete. Absence of evidence, not evidence of a problem."
},
"liveness": {
"type": "string",
"description": "Reachability: live, grace, degraded or dead."
},
"registryStatus": {
"type": "string",
"description": "active, deprecated or deleted."
},
"deletedAt": {
"type": [
"string",
"null"
],
"description": "When the registry removed it."
},
"statusMessage": {
"type": [
"string",
"null"
],
"description": "The registry's stated reason for a deprecated or deleted status, quoted from the publisher. Null when none was given, which is always the case while active."
},
"claimed": {
"type": "boolean",
"description": "Owner has proved ownership."
},
"matchedOn": {
"type": "string",
"enum": [
"slug",
"registry_name",
"package",
"remote_url"
],
"description": "Which form of identifier matched."
},
"malware": {
"type": "object",
"additionalProperties": false,
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"component",
"type",
"identifier",
"critical",
"severity",
"url"
],
"properties": {
"component": {
"type": "string",
"description": "The channel carrying the finding."
},
"type": {
"type": "string",
"description": "Ecosystem of that channel."
},
"identifier": {
"type": "string",
"description": "Package name or endpoint URL of that channel."
},
"critical": {
"type": "boolean",
"description": "The vendor's verdict was critical, which hard-zeroes the score."
},
"severity": {
"type": [
"string",
"null"
],
"description": "Vendor-reported severity for a non-critical finding; null when none was given."
},
"url": {
"type": "string",
"description": "Canonical page for the affected channel."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
}
}
},
"products": {
"type": "array",
"items": {
"type": "string"
},
"description": "Product slugs this server is classified as working with. Empty means either classified to nothing or not yet classified; the two are indistinguishable, and classification covers hosted remote endpoints only."
},
"siblingComponents": {
"type": "array",
"description": "Other channels of the same server, which may score differently.",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"component",
"type",
"score",
"url"
],
"properties": {
"component": {
"type": "string",
"description": "Channel slug."
},
"type": {
"type": "string",
"description": "Ecosystem."
},
"score": {
"type": [
"integer",
"null"
],
"description": "That channel's score."
},
"url": {
"type": "string",
"description": "Canonical page."
}
}
}
},
"tools": {
"type": "object",
"additionalProperties": false,
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"title",
"description",
"inputs",
"outputs",
"hasOutputSchema",
"hasExamples",
"tokenEstimate"
],
"properties": {
"name": {
"type": "string",
"description": "Tool name."
},
"title": {
"type": [
"string",
"null"
],
"description": "Human title, when distinct from name."
},
"description": {
"type": [
"string",
"null"
],
"description": "What the tool does."
},
"inputs": {
"type": "array",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"type",
"required",
"description"
],
"properties": {
"name": {
"type": "string",
"description": "Parameter name."
},
"type": {
"type": [
"string",
"null"
],
"description": "JSON scalar type, or null when unspecified."
},
"required": {
"type": "boolean",
"description": "Whether the tool requires this parameter."
},
"description": {
"type": [
"string",
"null"
],
"description": "Parameter documentation, if any."
}
}
},
"description": "Input parameters."
},
"outputs": {
"type": "array",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"type",
"required",
"description"
],
"properties": {
"name": {
"type": "string",
"description": "Parameter name."
},
"type": {
"type": [
"string",
"null"
],
"description": "JSON scalar type, or null when unspecified."
},
"required": {
"type": "boolean",
"description": "Whether the tool requires this parameter."
},
"description": {
"type": [
"string",
"null"
],
"description": "Parameter documentation, if any."
}
}
},
"description": "Output schema fields."
},
"hasOutputSchema": {
"type": "boolean",
"description": "Declares structured output."
},
"hasExamples": {
"type": "boolean",
"description": "Ships JSON-Schema examples."
},
"tokenEstimate": {
"type": "integer",
"description": "Approximate context tokens this tool's definition costs."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
}
}
},
"toolsTruncatedAtCapture": {
"type": "boolean",
"description": "Our capture hit a size bound, so the tool list may be incomplete."
},
"changes": {
"type": "object",
"additionalProperties": false,
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"id",
"kind",
"summary",
"materiality",
"direction",
"scoreDelta",
"occurredOn",
"url"
],
"properties": {
"id": {
"type": "string",
"description": "Event identifier."
},
"kind": {
"type": "string",
"description": "Machine-readable event kind, e.g. tool.removed."
},
"summary": {
"type": "string",
"description": "Plain-English description."
},
"materiality": {
"type": "string",
"enum": [
"critical",
"security",
"functional",
"cosmetic"
],
"description": "How much this change matters."
},
"direction": {
"type": "string",
"enum": [
"regression",
"improvement",
"neutral"
],
"description": "Whether this was a step back or forward."
},
"scoreDelta": {
"type": [
"integer",
"null"
],
"description": "Score movement attributed to it."
},
"occurredOn": {
"type": "string",
"description": "UTC date observed."
},
"url": {
"type": "string",
"description": "Deep link to the event."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
}
}
},
"url": {
"type": "string",
"description": "Canonical verifymcp.io page."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}🟢get_server_comparison(identifiers)
Compare up to 5 MCP servers side by side: trust scores, per-category breakdown, tool counts and context-token cost. Use when choosing between candidates that do the same job. Accepts package names, endpoint URLs, registry names or verifymcp slugs.
Input Schema
{
"type": "object",
"properties": {
"identifiers": {
"type": "array",
"minItems": 2,
"maxItems": 5,
"items": {
"type": "string"
},
"description": "Two to 5 servers to compare, as names, URLs or slugs."
}
},
"required": [
"identifiers"
],
"additionalProperties": false,
"examples": [
{
"identifiers": [
"@acme/mcp-server",
"@other/mcp-server"
]
},
{
"identifiers": [
"acme-tools",
"beta-tools",
"gamma-tools"
]
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"identifier",
"found",
"slug",
"name",
"score",
"status",
"channel",
"componentCount",
"toolCount",
"tokenFootprint",
"lastScoredAt",
"claimed",
"registryStatus",
"categories",
"url"
],
"properties": {
"identifier": {
"type": "string",
"description": "The identifier you supplied, echoed back."
},
"found": {
"type": "boolean",
"description": "False when nothing matched; all other fields are then null."
},
"slug": {
"type": [
"string",
"null"
],
"description": "Resolved verifymcp identifier."
},
"name": {
"type": [
"string",
"null"
],
"description": "Display name."
},
"score": {
"type": [
"integer",
"null"
],
"description": "Best trust score 0-100."
},
"status": {
"type": [
"string",
"null"
],
"description": "Scoring status."
},
"channel": {
"type": [
"string",
"null"
],
"description": "Best-scoring channel, e.g. remote or npm."
},
"componentCount": {
"type": [
"integer",
"null"
],
"description": "How many channels this server ships."
},
"toolCount": {
"type": [
"integer",
"null"
],
"description": "Tools advertised across remote channels."
},
"tokenFootprint": {
"type": [
"integer",
"null"
],
"description": "Approximate context tokens all its tools cost."
},
"lastScoredAt": {
"type": [
"string",
"null"
],
"description": "When the best channel was last scored."
},
"claimed": {
"type": "boolean",
"description": "Owner has proved ownership."
},
"registryStatus": {
"type": [
"string",
"null"
],
"description": "active, deprecated or deleted."
},
"categories": {
"type": "array",
"description": "Per-category comparison axes, from the best-scoring channel.",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"score",
"verdict",
"reasons"
],
"properties": {
"name": {
"type": "string",
"description": "Category name."
},
"score": {
"type": [
"integer",
"null"
],
"description": "Category score; null when pending."
},
"verdict": {
"type": "string",
"enum": [
"pass",
"partial",
"fail",
"unverified"
],
"description": "unverified means undetermined, NOT failed."
},
"reasons": {
"type": "array",
"items": {
"type": "string"
},
"description": "Plain-English findings."
}
}
}
},
"url": {
"type": [
"string",
"null"
],
"description": "Canonical verifymcp.io page."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}🟢list_products(query)
List the products MCP servers integrate with, such as github or notion, and how many servers cover each. Use to find the product slug that list_servers accepts.
Input Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"maxLength": 100,
"description": "Name fragment to match against product names and slugs."
}
},
"additionalProperties": false,
"examples": [
{},
{
"query": "git"
},
{
"query": "notion"
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"slug",
"name",
"tierA",
"serverCount",
"url"
],
"properties": {
"slug": {
"type": "string",
"description": "The value to pass as list_servers' product filter."
},
"name": {
"type": "string",
"description": "Product display name."
},
"tierA": {
"type": "boolean",
"description": "Has an editorial hub page on verifymcp.io."
},
"serverCount": {
"type": "integer",
"minimum": 0,
"description": "Listed servers classified under this product. A floor, not a census: see notice."
},
"url": {
"type": [
"string",
"null"
],
"description": "Hub page, or null when the product has none."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}🟢list_known_malware(status)
List MCP server components carrying a supply-chain malware finding. Use to check whether anything in the register is flagged before installing.
Input Schema
{
"type": "object",
"properties": {
"status": {
"type": "string",
"enum": [
"active",
"unverified",
"cleared",
"all"
],
"default": "active",
"description": "Which findings to return: active, unverified, cleared or all. Defaults to active."
}
},
"additionalProperties": false,
"examples": [
{},
{
"status": "active"
},
{
"status": "all"
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"serverSlug",
"serverName",
"component",
"registryType",
"packageIdentifier",
"versionChecked",
"state",
"critical",
"severity",
"llmOnly",
"code",
"vendor",
"firstFlaggedOn",
"flaggedOnOrBefore",
"lastConfirmedOn",
"clearedOn",
"lastCheckedOn",
"score",
"registryDeleted",
"url",
"vendorUrl"
],
"properties": {
"serverSlug": {
"type": "string",
"description": "Pass to get_server for the full report."
},
"serverName": {
"type": "string",
"description": "Display name of the affected server."
},
"component": {
"type": "string",
"description": "The affected channel's slug."
},
"registryType": {
"type": "string",
"description": "Ecosystem: npm, pypi or nuget."
},
"packageIdentifier": {
"type": "string",
"description": "The flagged package."
},
"versionChecked": {
"type": [
"string",
"null"
],
"description": "Version the verdict pertained to; null when the scan recorded none."
},
"state": {
"type": "string",
"enum": [
"active",
"unverified",
"cleared"
],
"description": "active: still flagged. unverified: the finding was replaced by an inconclusive read. cleared: a later scan came back clean."
},
"critical": {
"type": "boolean",
"description": "Vendor graded it critical, which floors the component's score to zero."
},
"severity": {
"type": [
"string",
"null"
],
"description": "Vendor severity; null when none was given."
},
"llmOnly": {
"type": "boolean",
"description": "Every indicator is a model's suspicion with no signature match. Report it as suspicion, never as a detection."
},
"code": {
"type": "string",
"description": "The reason code recorded for the finding."
},
"vendor": {
"type": "string",
"description": "Which scanner answered."
},
"firstFlaggedOn": {
"type": "string",
"description": "UTC day OUR scan first recorded it. Not a vendor detection date; no vendor publishes one."
},
"flaggedOnOrBefore": {
"type": "boolean",
"description": "It was already present on the oldest reading we hold, so it began on or before that day."
},
"lastConfirmedOn": {
"type": "string",
"description": "Most recent UTC day a finding was confirmed."
},
"clearedOn": {
"type": [
"string",
"null"
],
"description": "Cleared rows only: first clean day."
},
"lastCheckedOn": {
"type": "string",
"description": "Newest day we hold any reading for this component."
},
"score": {
"type": [
"integer",
"null"
],
"description": "The component's trust score; null when never scored."
},
"registryDeleted": {
"type": "boolean",
"description": "The registry has since dropped this server."
},
"url": {
"type": "string",
"description": "Canonical page carrying the full breakdown."
},
"vendorUrl": {
"type": [
"string",
"null"
],
"description": "The vendor's own report, when it indexes this ecosystem."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}🟢get_server_alternatives(identifier)
Other MCP servers doing a similar job to a given one, with their trust scores. Neighbours share a product or publisher namespace; this is not a semantic search.
Input Schema
{
"type": "object",
"properties": {
"identifier": {
"type": "string",
"description": "Package name, endpoint URL, registry name or verifymcp slug."
}
},
"required": [
"identifier"
],
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"identifier": "acme-tools"
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"slug",
"component",
"name",
"score",
"reason",
"status",
"url"
],
"properties": {
"slug": {
"type": "string",
"description": "Pass to get_server for the full report."
},
"component": {
"type": [
"string",
"null"
],
"description": "The channel url points at; null when it has none."
},
"name": {
"type": "string",
"description": "Display name."
},
"score": {
"type": [
"integer",
"null"
],
"description": "Trust score 0-100; null when unscored."
},
"reason": {
"type": "string",
"description": "Why it is a neighbour: a shared product, or a shared publisher namespace. Not an endorsement."
},
"status": {
"type": [
"string",
"null"
],
"description": "deprecated, dead and so on; null for a healthy server."
},
"url": {
"type": "string",
"description": "Canonical verifymcp.io page."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}🟢get_server_diagnostics(identifier, component)
The evidence behind one server's score: TLS, DNSSEC, authorization, redirects, transports, provenance, install scripts, known CVEs and dependency health. Use to explain a low score.
Input Schema
{
"type": "object",
"properties": {
"identifier": {
"type": "string",
"description": "Package name, endpoint URL, registry name or verifymcp slug."
},
"component": {
"type": "string",
"description": "Which channel to report on when a server ships several."
}
},
"required": [
"identifier"
],
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"identifier": "io.github.acme/tools",
"component": "npm"
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"required": [
"slug",
"component",
"capturedAt",
"track",
"endpoint",
"declaredUrl",
"captureTruncated",
"tls",
"dnssec",
"auth",
"redirect",
"transports",
"provenance",
"installScripts",
"vulnerabilities",
"dependencies",
"url"
],
"properties": {
"slug": {
"type": "string",
"description": "Stable verifymcp identifier."
},
"component": {
"type": "string",
"description": "Channel these diagnostics belong to."
},
"capturedAt": {
"type": [
"string",
"null"
],
"description": "When the probe ran; null when never."
},
"track": {
"type": [
"string",
"null"
],
"description": "Which probe produced this: remote or package."
},
"endpoint": {
"type": [
"string",
"null"
],
"description": "The URL actually probed, after any redirect."
},
"declaredUrl": {
"type": [
"string",
"null"
],
"description": "The registry-declared URL, when it differs from the one probed."
},
"captureTruncated": {
"type": "boolean",
"description": "The capture was trimmed to fit its storage bound, so sections may be missing."
},
"tls": {
"type": [
"object",
"null"
],
"description": "Handshake outcome, negotiated version, cipher and certificate chain summaries. Null when not captured."
},
"dnssec": {
"type": [
"object",
"null"
],
"description": "The DNSSEC validation walk, root to leaf. Null when not captured."
},
"auth": {
"type": [
"object",
"null"
],
"description": "Authorization posture: the gate, the challenge, and RFC 9728 metadata. Null when not captured."
},
"redirect": {
"type": [
"object",
"null"
],
"description": "The plaintext http:// probe behind the HTTPS-enforcement check. Null when not captured."
},
"transports": {
"type": "object",
"additionalProperties": false,
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"description": "One transport probe: which was offered and whether we could speak it."
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
}
}
},
"provenance": {
"type": [
"object",
"null"
],
"description": "Attestation and signing evidence for a published package. Null when not captured."
},
"installScripts": {
"type": "object",
"additionalProperties": false,
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"description": "A lifecycle hook found in the package manifest, with the review tier assigned to it."
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
}
}
},
"vulnerabilities": {
"type": "object",
"additionalProperties": false,
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"description": "A known vulnerability affecting the dependency tree, with its CVE or advisory id."
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
}
}
},
"dependencies": {
"type": [
"object",
"null"
],
"description": "Dependency-tree counts. `partial` true means the tree did not fully resolve and counts undercount."
},
"url": {
"type": "string",
"description": "Canonical verifymcp.io page."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}🟢get_server_install_config(identifier, component)
Ready-to-paste install snippets for one MCP server, for every client we support. An MCPB bundle has no launch command, so it returns the download URL, the registry's SHA-256 and commands to verify the file instead. Read get_server first: this returns configuration, not a safety judgement.
Input Schema
{
"type": "object",
"properties": {
"identifier": {
"type": "string",
"description": "Package name, endpoint URL, registry name or verifymcp slug."
},
"component": {
"type": "string",
"description": "Which channel to report on when a server ships several."
}
},
"required": [
"identifier"
],
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"identifier": "acme-tools",
"component": "npm"
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"client",
"label",
"lang",
"comment",
"body",
"note"
],
"properties": {
"client": {
"type": "string",
"description": "Client id, e.g. claude, cursor, vscode."
},
"label": {
"type": "string",
"description": "Client display name."
},
"lang": {
"type": "string",
"enum": [
"bash",
"json",
"toml",
"yaml"
],
"description": "Snippet language."
},
"comment": {
"type": "string",
"description": "Leading comment line, e.g. where the block goes."
},
"body": {
"type": "string",
"description": "The snippet itself. Use verbatim; never re-escape it."
},
"note": {
"type": [
"string",
"null"
],
"description": "Caveat for this client, where the syntax is a convention rather than a guarantee."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
},
"context": {
"type": [
"object",
"null"
],
"additionalProperties": false,
"required": [
"score",
"status",
"verdict",
"malwareScan",
"claimed",
"publisherClass",
"url"
],
"description": "What we know about the server being installed. Present whenever a server resolved, including when no snippets could be built; null only when the identifier matched nothing.",
"properties": {
"score": {
"type": [
"integer",
"null"
],
"description": "Trust score 0-100; null when never scored."
},
"status": {
"type": [
"string",
"null"
],
"description": "Scoring status for this channel."
},
"verdict": {
"type": "string",
"enum": [
"pass",
"partial",
"fail",
"unverified"
],
"description": "Worst category verdict. unverified means we could not determine it, NOT that it failed."
},
"malwareScan": {
"type": "string",
"enum": [
"confirmed",
"clean",
"not_scanned"
],
"description": "confirmed: a vendor flagged this server. clean: a vendor assessed it and found nothing. not_scanned: nobody assessed it, which is NOT an all-clear."
},
"claimed": {
"type": "boolean",
"description": "Owner has proved ownership of the listing."
},
"publisherClass": {
"type": "string",
"description": "official, verified, third_party or unknown. unknown means no proof, not disproof."
},
"url": {
"type": "string",
"description": "Canonical page carrying the full report."
}
}
},
"bundle": {
"type": [
"object",
"null"
],
"additionalProperties": false,
"required": [
"url",
"sha256",
"fileName",
"verify"
],
"description": "MCPB bundles only (null otherwise): the file to download, the SHA-256 the registry declares for it, and commands that check the download against it. Open the verified file with an MCPB-capable host such as Claude Desktop.",
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Download URL of the .mcpb bundle."
},
"sha256": {
"type": [
"string",
"null"
],
"pattern": "^[0-9a-f]{64}$",
"description": "Lowercase hex SHA-256 the registry declares for the file; null when it declares none, so there is nothing to verify against."
},
"fileName": {
"type": "string",
"description": "File name the verify commands expect the download to be saved as."
},
"verify": {
"type": "array",
"description": "Commands that check the downloaded file against sha256. Empty when sha256 is null.",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"id",
"label",
"lang",
"body"
],
"properties": {
"id": {
"type": "string",
"description": "shasum or powershell."
},
"label": {
"type": "string",
"description": "Where the command runs."
},
"lang": {
"type": "string",
"enum": [
"bash",
"powershell"
]
},
"body": {
"type": "string",
"description": "The command. Use verbatim."
}
}
}
}
}
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source",
"context",
"bundle"
],
"additionalProperties": false
}🟢get_server_tools(identifier, component)
Every tool one MCP server exposes, with its parameters, output schema and context-token cost. Use when get_server reported the tool list was truncated.
Input Schema
{
"type": "object",
"properties": {
"identifier": {
"type": "string",
"description": "Package name, endpoint URL, registry name or verifymcp slug."
},
"component": {
"type": "string",
"description": "Which channel to report on when a server ships several."
}
},
"required": [
"identifier"
],
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"identifier": "acme-tools",
"component": "npm"
}
]
}Output Schema
{
"type": "object",
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"slug",
"component",
"tokenFootprint",
"truncatedAtCapture",
"tools",
"url"
],
"properties": {
"slug": {
"type": "string",
"description": "Stable verifymcp identifier."
},
"component": {
"type": "string",
"description": "Channel these tools belong to."
},
"tokenFootprint": {
"type": "integer",
"minimum": 0,
"description": "Total estimated context tokens for every tool listed here."
},
"truncatedAtCapture": {
"type": "boolean",
"description": "The server itself truncated its tool list when we captured it, so it may expose more."
},
"tools": {
"type": "object",
"additionalProperties": false,
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"properties": {
"items": {
"type": "array",
"maxItems": 100,
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"title",
"description",
"inputs",
"outputs",
"hasOutputSchema",
"hasExamples",
"tokenEstimate"
],
"properties": {
"name": {
"type": "string",
"description": "Tool name."
},
"title": {
"type": [
"string",
"null"
],
"description": "Human title, when distinct from name."
},
"description": {
"type": [
"string",
"null"
],
"description": "What the tool does."
},
"inputs": {
"type": "array",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"type",
"required",
"description"
],
"properties": {
"name": {
"type": "string",
"description": "Parameter name."
},
"type": {
"type": [
"string",
"null"
],
"description": "JSON scalar type, or null when unspecified."
},
"required": {
"type": "boolean",
"description": "Whether the tool requires this parameter."
},
"description": {
"type": [
"string",
"null"
],
"description": "Parameter documentation, if any."
}
}
},
"description": "Input parameters."
},
"outputs": {
"type": "array",
"items": {
"type": "object",
"additionalProperties": false,
"required": [
"name",
"type",
"required",
"description"
],
"properties": {
"name": {
"type": "string",
"description": "Parameter name."
},
"type": {
"type": [
"string",
"null"
],
"description": "JSON scalar type, or null when unspecified."
},
"required": {
"type": "boolean",
"description": "Whether the tool requires this parameter."
},
"description": {
"type": [
"string",
"null"
],
"description": "Parameter documentation, if any."
}
}
},
"description": "Output schema fields."
},
"hasOutputSchema": {
"type": "boolean",
"description": "Declares structured output."
},
"hasExamples": {
"type": "boolean",
"description": "Ships JSON-Schema examples."
},
"tokenEstimate": {
"type": "integer",
"description": "Approximate context tokens this tool's definition costs."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
}
}
},
"url": {
"type": "string",
"description": "Canonical verifymcp.io page."
}
}
}
},
"count": {
"type": "integer",
"minimum": 0,
"description": "Number of entries in items."
},
"total": {
"type": "integer",
"minimum": 0,
"description": "Matches before the 100-item cap."
},
"truncated": {
"type": "boolean",
"description": "True when total exceeds count."
},
"notice": {
"type": [
"string",
"null"
],
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies."
},
"asOf": {
"type": "string",
"format": "date-time",
"description": "When this data was read (UTC)."
},
"source": {
"type": "string",
"format": "uri",
"description": "Canonical verifymcp.io page for this result."
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"additionalProperties": false
}Recommended Prompts
get_serverget_serverlist_serverslist_serverslist_serversget_serverCommunity
Evidence