BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

mcptrustchecker

Connector Security Usable
Works inClaude Code Claude Cowork Claude Chat
Usable Scanned — metadata only

Validates MCP server integrity by inspecting actual published source code rather than metadata alone, reducing supply-chain compromise risk and tool-poisonin…

Security scanner for MCP (Model Context Protocol) servers — reads the real published npm/PyPI source, not just metadata, to catch tool poisoning, prompt injection, toxic flows & supply-chain risk. Offline, deterministic A–F Trust Score, SARIF + CI gates.

89 starsMIT (commercial OK)FreeNo code needed
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Validates MCP server integrity by inspecting actual published source code rather than metadata alone, reducing supply-chain compromise risk and tool-poisoning attacks before integration into production AI pipelines.

Security teams and platform engineers vetting third-party MCP servers before enterprise adoption and CI/CD integration.

Claude Code Claude Cowork Claude Chat

https://github.com/illiahaidar/mcptrustchecker

By illiahaidar

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
claude mcp add mcptrustchecker -- npx -y mcptrustchecker

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.

First thing to try

Once it’s connected, paste this into Claude:

Scan an MCP server dependency for supply chain vulnerabilities before integrating it
CostFree

Trust Signals Auto-scanned

Stars89Last updated2026-07-22LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-23 · scanner v1

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse New

No community discussions found yet. This doesn't mean the tool isn't good — it may be new or serve a niche use case.

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 89 GitHub stars; contributors unknown; last commit 1d ago; license MIT.

Things to check

  • Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
3/5
Overall score3.00 / 5.00 UsableEvaluatedJul 2026
Scored from trust signals (evidence-eval-v1): 89 GitHub stars; contributors unknown; last commit 1d ago; license MIT.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →