VerifyMCP
by verifymcp.io in Security & trust
Independent trust scores, tool surfaces and change history for MCP servers.
https://mcp.verifymcp.io
Last 30 days
- Uptime
- 100%
- Response time
- 233 ms typical, 233 ms slowest 5%
- Last check
- 3 h ago
- Next check
- in 3 h
How to call it
Add it to any MCP client that supports remote servers.
{
"mcpServers": {
"verifymcp": {
"type": "http",
"url": "https://mcp.verifymcp.io"
}
}
}9 tools
- list_servers
Filter the VerifyMCP directory of scored MCP servers. Use to discover servers by name fragment, ecosystem, product or trust score. Name matching only: descriptions and capabilities are not searched, so a plain-English question matches nothing. Returns the first 100.
- get_server
Get the full VerifyMCP trust report for one MCP server: score with per-category verdicts and reasons, the tools it exposes with their context-token cost, and its recent change history. Use before installing or trusting a server. Accepts a package name, endpoint URL, registry name
- get_server_comparison
Compare up to 5 MCP servers side by side: trust scores, per-category breakdown, tool counts and context-token cost. Use when choosing between candidates that do the same job. Accepts package names, endpoint URLs, registry names or verifymcp slugs.
- list_products
List the products MCP servers integrate with, such as github or notion, and how many servers cover each. Use to find the product slug that list_servers accepts.
- list_known_malware
List MCP server components carrying a supply-chain malware finding. Use to check whether anything in the register is flagged before installing.
- get_server_alternatives
Other MCP servers doing a similar job to a given one, with their trust scores. Neighbours share a product or publisher namespace; this is not a semantic search.
- get_server_diagnostics
The evidence behind one server's score: TLS, DNSSEC, authorization, redirects, transports, provenance, install scripts, known CVEs and dependency health. Use to explain a low score.
- get_server_install_config
Ready-to-paste install snippets for one MCP server, for every client we support. An MCPB bundle has no launch command, so it returns the download URL, the registry's SHA-256 and commands to verify the file instead. Read get_server first: this returns configuration, not a safety j
- get_server_tools
Every tool one MCP server exposes, with its parameters, output schema and context-token cost. Use when get_server reported the tool list was truncated.
Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time |
|---|---|---|---|
| 3 h ago | Passed | 200 | 233 ms |