registry

The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
98%
命名の品質
100%
ポイズニングのリスク
80%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(2)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains URL to non-standard domainget_change_events 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~818トークン数(ツール定義)
~905 B一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 0.64%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "registry": {
      "url": "https://api.policylayer.com/mcp"
    }
  }
}

リモートエンドポイント

https://api.policylayer.com/mcpstreamable-http

できること

ツール一覧

ツール(5)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢check_mcp_server(server)

Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk grade, auth posture, freshness, and the tool surface listed riskiest-first. A server the registry does not know is queued for scanning by this very call — check back shortly.

入力スキーマ

{
  "type": "object",
  "properties": {
    "server": {
      "type": "string",
      "description": "Registry slug, npm package name (e.g. @acme/mcp-server), remote URL, or server name."
    }
  },
  "required": [
    "server"
  ]
}
🟢check_mcp_stack(servers)

Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdict (attention signals and a suggested action) — and the lookup status for every miss; counts, grades and flagged tools come from the published records only. Costs one rate-limit unit per server.

入力スキーマ

{
  "type": "object",
  "properties": {
    "servers": {
      "type": "array",
      "maxItems": 25,
      "description": "One entry per server in the stack.",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "description": "Your label for this server (e.g. its config key) — echoed back on the result."
          },
          "candidates": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "maxItems": 5,
            "description": "Identifiers to try in order: npm package name, registry slug, or remote URL. Most package-like first."
          }
        },
        "required": [
          "candidates"
        ]
      }
    }
  },
  "required": [
    "servers"
  ]
}
🟢search_registry(query, limit)

Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand) and tool count — follow up with check_mcp_server on the match you meant.

入力スキーマ

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Substring to match against slug, name and packages."
    },
    "limit": {
      "type": "number",
      "description": "Max matches to return (1-20, default 10)."
    }
  },
  "required": [
    "query"
  ]
}
🟢check_tool(server, tool)

One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. "should execute_sql on this server be permitted?"

入力スキーマ

{
  "type": "object",
  "properties": {
    "server": {
      "type": "string",
      "description": "Registry slug or npm package name of the server."
    },
    "tool": {
      "type": "string",
      "description": "Tool name as the server declares it."
    }
  },
  "required": [
    "server",
    "tool"
  ]
}
🟡get_change_events(after_id, limit, severity)

The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at https://policylayer.com/registry/pricing.

入力スキーマ

{
  "type": "object",
  "properties": {
    "after_id": {
      "type": "number",
      "description": "Return events with id greater than this cursor (default 0)."
    },
    "limit": {
      "type": "number",
      "description": "Max events (1-1000, default 200)."
    },
    "severity": {
      "type": "string",
      "enum": [
        "info",
        "notice",
        "warning",
        "critical"
      ],
      "description": "Minimum severity: that level and above."
    }
  }
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 5 件
検証済みバージョンは記録されていませんツール 5 件