io.verifymcp/mcp

VerifyMCP

Independent trust scores, tool surfaces and change history for MCP servers.

1.0.0
Version
remote
Transport
9
Tools

Security review

Review passed

Reviewed 23h ago.

  • tools: 9 tools scanned
  • metadata: scanned

No findings.

Tools (9)

  • list_servers

    Filter the VerifyMCP directory of scored MCP servers. Use to discover servers by name fragment, ecosystem, product or trust score. Name matching only: descriptions and capabilities are not searched, so a plain-English question matches nothing. Returns the first 100.

  • get_server

    Get the full VerifyMCP trust report for one MCP server: score with per-category verdicts and reasons, the tools it exposes with their context-token cost, and its recent change history. Use before installing or trusting a server. Accepts a package name, endpoint URL, registry name or verifymcp slug.

  • get_server_comparison

    Compare up to 5 MCP servers side by side: trust scores, per-category breakdown, tool counts and context-token cost. Use when choosing between candidates that do the same job. Accepts package names, endpoint URLs, registry names or verifymcp slugs.

  • list_products

    List the products MCP servers integrate with, such as github or notion, and how many servers cover each. Use to find the product slug that list_servers accepts.

  • list_known_malware

    List MCP server components carrying a supply-chain malware finding. Use to check whether anything in the register is flagged before installing.

  • get_server_alternatives

    Other MCP servers doing a similar job to a given one, with their trust scores. Neighbours share a product or publisher namespace; this is not a semantic search.

  • get_server_diagnostics

    The evidence behind one server's score: TLS, DNSSEC, authorization, redirects, transports, provenance, install scripts, known CVEs and dependency health. Use to explain a low score.

  • get_server_install_config

    Ready-to-paste install snippets for one MCP server, for every client we support. An MCPB bundle has no launch command, so it returns the download URL, the registry's SHA-256 and commands to verify the file instead. Read get_server first: this returns configuration, not a safety judgement.

  • get_server_tools

    Every tool one MCP server exposes, with its parameters, output schema and context-token cost. Use when get_server reported the tool list was truncated.