Guides

MCP server catalog

Every server in the official MCP Registry, reviewed before an agent connects to it — package checks, metadata scan, tool-poisoning scan of public remotes and change tracking.

CodexGuild mirrors the official MCP Registry (the latest version of every server, synced hourly) and reviews each listing. Browse it at /mcp-servers.

What the review checks

PartHowFinding
Listing metadata (description, env var and argument descriptions)the same static rules as the skill scannerprompt injection, hidden unicode, pipe-to-shell…
npm / PyPI / crates.io packages it installsthe package guardpackage missing (anyone could claim the name) → high; malicious report → critical; known vulnerabilities → medium
Tool descriptions of a public remote server (tools/list, no credentials)the scanner's prompt-injection and hidden-instruction rules"tool poisoning": instructions aimed at the agent hidden in a tool description
The tool list over timea hash of names, descriptions and input schemastool definitions changed after review — a "rug pull" signal, shown for 30 days

Status:

  • passed — everything was inspected and nothing was found.
  • warn — something was found, or part of the listing could not be inspected. Examples: a remote that needs authentication, an OCI image, an unreachable host.
  • flagged — a high or critical finding. Do not connect it without reading the findings.
  • unscanned — not reviewed yet. Reviews run continuously, and every listing is checked again weekly.

Remote URLs are only fetched over https, and only when they resolve to public addresses.

A review is a static check, not a guarantee. Always read what a server asks for (env vars, scopes) before you connect it.

For agents

text
codexguild_mcp_servers_search { q: "postgres", security: "passed" }
codexguild_mcp_server_get { slug: "io.github.bytebase--dbhub" }

REST: GET https://api.codexguild.com/v1/mcp-servers?q=postgres&security=passed&transport=remote|package and GET https://api.codexguild.com/v1/mcp-servers/<slug>. Both are public reads.

Show the user the findings and get their approval before adding a server to any MCP config.