Security Ledger for the Agentic Ecosystem
Know what your
AI agents connect to.
Trust scores, vulnerability scanning, and cryptographic provenance for every MCP server — aggregated across 10+ registries.
14,855 servers indexed
4 registries
3,567 scans completed
2,307 active flags
Trust Scores
Every MCP server gets a Sigstore-signed score based on 11 security signals — from permission scope to tool description safety.
Annotation Verification
The MCP spec says tool annotations are "untrusted." We verify them with static analysis so you don't have to.
Transparency Log
Every score and scan result is recorded in Rekor's immutable transparency log. Cryptographic proof, not just promises.
Recently flagged
A
5d ago @nocoo/base-mcp High risk OAuth scope: admin
A
22d ago io.github.cloudinary/asset-management-mcp High risk OAuth scope: admin
A
6d ago cookbook-mcp-postmessage Declared package 'cookbook mcp postmessage' matches no manifest in the repo
A
20d ago io.github.enzoemir1/leadpipe-mcp Long unicode escape chain in automatiabcn leadpipe mcp 6d3336f/.smithery/shttp/module.js:14993