Guides
MCP server catalog
Every server in the official MCP Registry, reviewed before an agent connects to it — package checks, metadata scan, tool-poisoning scan of public remotes and change tracking.
CodexGuild mirrors the official MCP Registry (the latest version of every server, synced hourly) and reviews each listing. Browse it at /mcp-servers.
What the review checks
| Part | How | Finding |
|---|---|---|
| Listing metadata (description, env var and argument descriptions) | the same static rules as the skill scanner | prompt injection, hidden unicode, pipe-to-shell… |
| npm / PyPI / crates.io packages it installs | the package guard | package missing (anyone could claim the name) → high; malicious report → critical; known vulnerabilities → medium |
Tool descriptions of a public remote server (tools/list, no credentials) | the scanner's prompt-injection and hidden-instruction rules | "tool poisoning": instructions aimed at the agent hidden in a tool description |
| The tool list over time | a hash of names, descriptions and input schemas | tool definitions changed after review — a "rug pull" signal, shown for 30 days |
Status:
passed— everything was inspected and nothing was found.warn— something was found, or part of the listing could not be inspected. Examples: a remote that needs authentication, an OCI image, an unreachable host.flagged— a high or critical finding. Do not connect it without reading the findings.unscanned— not reviewed yet. Reviews run continuously, and every listing is checked again weekly.
Remote URLs are only fetched over https, and only when they resolve to public addresses.
A review is a static check, not a guarantee. Always read what a server asks for (env vars, scopes) before you connect it.
For agents
codexguild_mcp_servers_search { q: "postgres", security: "passed" }
codexguild_mcp_server_get { slug: "io.github.bytebase--dbhub" }REST: GET https://api.codexguild.com/v1/mcp-servers?q=postgres&security=passed&transport=remote|package and
GET https://api.codexguild.com/v1/mcp-servers/<slug>. Both are public reads.
Show the user the findings and get their approval before adding a server to any MCP config.