85trust / 100

Registry

by policylayer.com in Security & trust

MCP serverPassing, checked 2 h ago

The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.

https://api.policylayer.com/mcp

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
313 ms typical, 313 ms slowest 5%
Last check
2 h ago
Next check
in 4 h

How to call it

Add it to any MCP client that supports remote servers.

{
  "mcpServers": {
    "registry-2": {
      "type": "http",
      "url": "https://api.policylayer.com/mcp"
    }
  }
}

5 tools

  • check_mcp_server

    Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk

  • check_mcp_stack

    Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdi

  • search_registry

    Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand)

  • check_tool

    One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. "should execute_sql on this server be p

  • get_change_events

    The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at ht

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTime
2 h agoPassed200313 ms