servers / mcptrustchecker

mcptrustchecker MCP server

communitystdiolocalbrokenbroken

Security scanner for MCP (Model Context Protocol) servers — reads the real published npm/PyPI source, not just metadata, to catch tool poisoning, prompt injection, toxic flows & supply-chain risk. Offline, deterministic A–F Trust Score, SARIF + CI gates.


01Tools · 0
Tools require a live tools/list handshake. For local/stdio servers that runs in a sandbox (gated off until configured); remote servers are probed directly.

02Install & source
npx -y mcptrustchecker
npx

05Provenance & freshness
sourcesGitHub repo search [p4]
last_checked2026-09-07 16:55Z
next_check2026-09-07 19:55Z
cadenceevery 3h
verifiedmetadata:failed metadata:failed tools_list:skipped handshake:skipped metadata:passed metadata:failed metadata:failed metadata:failed metadata:failed metadata:failed
index_statusindex7 unique facts >= 5

06Badge

Add the “as seen on MCPExplorer” badge to your README. mcptrustchecker MCP — as seen on mcpexplorer.com

[![mcptrustchecker MCP — as seen on mcpexplorer.com](https://mcpexplorer.com/badge/mcptrustchecker.svg)](https://mcpexplorer.com/servers/mcptrustchecker)

Next step

This is one server. A loadout combines the right servers, governance, and proven plays for a whole job — assembled deliberately, not tool-dumped.

Explore loadouts →