registry
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
我該用這個嗎
品質與安全性
發現項目(2)
- HIGH
- MEDIUM在 get_change_events 中
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"registry": {
"url": "https://api.policylayer.com/mcp"
}
}
}遠端端點
https://api.policylayer.com/mcpstreamable-http它能做什麼
工具清單
工具(5)
🟢check_mcp_server(server)
Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk grade, auth posture, freshness, and the tool surface listed riskiest-first. A server the registry does not know is queued for scanning by this very call — check back shortly.
輸入結構描述
{
"type": "object",
"properties": {
"server": {
"type": "string",
"description": "Registry slug, npm package name (e.g. @acme/mcp-server), remote URL, or server name."
}
},
"required": [
"server"
]
}🟢check_mcp_stack(servers)
Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdict (attention signals and a suggested action) — and the lookup status for every miss; counts, grades and flagged tools come from the published records only. Costs one rate-limit unit per server.
輸入結構描述
{
"type": "object",
"properties": {
"servers": {
"type": "array",
"maxItems": 25,
"description": "One entry per server in the stack.",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Your label for this server (e.g. its config key) — echoed back on the result."
},
"candidates": {
"type": "array",
"items": {
"type": "string"
},
"maxItems": 5,
"description": "Identifiers to try in order: npm package name, registry slug, or remote URL. Most package-like first."
}
},
"required": [
"candidates"
]
}
}
},
"required": [
"servers"
]
}🟢search_registry(query, limit)
Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand) and tool count — follow up with check_mcp_server on the match you meant.
輸入結構描述
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Substring to match against slug, name and packages."
},
"limit": {
"type": "number",
"description": "Max matches to return (1-20, default 10)."
}
},
"required": [
"query"
]
}🟢check_tool(server, tool)
One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. "should execute_sql on this server be permitted?"
輸入結構描述
{
"type": "object",
"properties": {
"server": {
"type": "string",
"description": "Registry slug or npm package name of the server."
},
"tool": {
"type": "string",
"description": "Tool name as the server declares it."
}
},
"required": [
"server",
"tool"
]
}🟡get_change_events(after_id, limit, severity)
The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at https://policylayer.com/registry/pricing.
輸入結構描述
{
"type": "object",
"properties": {
"after_id": {
"type": "number",
"description": "Return events with id greater than this cursor (default 0)."
},
"limit": {
"type": "number",
"description": "Max events (1-1000, default 200)."
},
"severity": {
"type": "string",
"enum": [
"info",
"notice",
"warning",
"critical"
],
"description": "Minimum severity: that level and above."
}
}
}社群
證據