mcptrustchecker
Validates MCP server integrity by inspecting actual published source code rather than metadata alone, reducing supply-chain compromise risk and tool-poisonin…
Security scanner for MCP (Model Context Protocol) servers — reads the real published npm/PyPI source, not just metadata, to catch tool poisoning, prompt injection, toxic flows & supply-chain risk. Offline, deterministic A–F Trust Score, SARIF + CI gates.
- Ask Claude to scan an MCP server dependency for supply chain vulnerabilities before integrating it.
- Generate a security report with Trust Score ratings for all MCP packages in your project.
- Automate CI/CD gates that block deployment if MCP server Trust Scores fall below your threshold.
Validates MCP server integrity by inspecting actual published source code rather than metadata alone, reducing supply-chain compromise risk and tool-poisoning attacks before integration into production AI pipelines.
Security teams and platform engineers vetting third-party MCP servers before enterprise adoption and CI/CD integration.
https://github.com/illiahaidar/mcptrustchecker
By illiahaidar
How to Get It
claude mcp add mcptrustchecker -- npx -y mcptrustchecker
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Auto-generated from the tool's public listing — not hands-on verified. Cross-check against the source repo's README before running.
Once it’s connected, paste this into Claude:
Scan an MCP server dependency for supply chain vulnerabilities before integrating it
Trust Signals Auto-scanned
Data & Access
Community Pulse New
No community discussions found yet. This doesn't mean the tool isn't good — it may be new or serve a niche use case.
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
Scored from trust signals (evidence-eval-v1): 89 GitHub stars; contributors unknown; last commit 1d ago; license MIT.
Things to check
- Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
Scored from trust signals (evidence-eval-v1): 89 GitHub stars; contributors unknown; last commit 1d ago; license MIT.