registry
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
사용해야 할까요
품질 및 안전성
발견 사항 (2)
- HIGH
- MEDIUMget_change_events에서
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"registry": {
"url": "https://api.policylayer.com/mcp"
}
}
}원격 엔드포인트
https://api.policylayer.com/mcpstreamable-http할 수 있는 일
도구 목록
도구 (5)
🟢check_mcp_server(server)
Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk grade, auth posture, freshness, and the tool surface listed riskiest-first. A server the registry does not know is queued for scanning by this very call — check back shortly.
입력 스키마
{
"type": "object",
"properties": {
"server": {
"type": "string",
"description": "Registry slug, npm package name (e.g. @acme/mcp-server), remote URL, or server name."
}
},
"required": [
"server"
]
}🟢check_mcp_stack(servers)
Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdict (attention signals and a suggested action) — and the lookup status for every miss; counts, grades and flagged tools come from the published records only. Costs one rate-limit unit per server.
입력 스키마
{
"type": "object",
"properties": {
"servers": {
"type": "array",
"maxItems": 25,
"description": "One entry per server in the stack.",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Your label for this server (e.g. its config key) — echoed back on the result."
},
"candidates": {
"type": "array",
"items": {
"type": "string"
},
"maxItems": 5,
"description": "Identifiers to try in order: npm package name, registry slug, or remote URL. Most package-like first."
}
},
"required": [
"candidates"
]
}
}
},
"required": [
"servers"
]
}🟢search_registry(query, limit)
Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand) and tool count — follow up with check_mcp_server on the match you meant.
입력 스키마
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Substring to match against slug, name and packages."
},
"limit": {
"type": "number",
"description": "Max matches to return (1-20, default 10)."
}
},
"required": [
"query"
]
}🟢check_tool(server, tool)
One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. "should execute_sql on this server be permitted?"
입력 스키마
{
"type": "object",
"properties": {
"server": {
"type": "string",
"description": "Registry slug or npm package name of the server."
},
"tool": {
"type": "string",
"description": "Tool name as the server declares it."
}
},
"required": [
"server",
"tool"
]
}🟡get_change_events(after_id, limit, severity)
The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at https://policylayer.com/registry/pricing.
입력 스키마
{
"type": "object",
"properties": {
"after_id": {
"type": "number",
"description": "Return events with id greater than this cursor (default 0)."
},
"limit": {
"type": "number",
"description": "Max events (1-1000, default 200)."
},
"severity": {
"type": "string",
"enum": [
"info",
"notice",
"warning",
"critical"
],
"description": "Minimum severity: that level and above."
}
}
}커뮤니티
증거