Server definition
- Hash
- sha256:2b4f1ff6dc4556921174b3a908ac237fbbd8b3c169c1113ff1f0eab3bd088920
- What it is
- What a remote MCP server returned when asked what it offers: 9 tools
The blob, as servednamed by its sha256
{
"instructions": "VerifyMCP publishes independent trust scores for MCP servers.\n\nFind servers with list_servers (name, ecosystem, product or score); list_products has the\nproduct slugs. Use get_server before installing or trusting one: score with per-category\nverdicts, any malware finding, the tools it exposes with their context cost, and recent\nchanges. Then get_server_diagnostics for the evidence behind a weak score,\nget_server_comparison or get_server_alternatives to choose between candidates,\nget_server_tools for a truncated tool list, get_server_install_config once decided, and\nlist_known_malware for everything flagged.\n\nA verdict of \"unverified\" means a check could not be completed. It is not a\nfailure, and should not be reported as one.",
"tools": [
{
"description": "Get the full VerifyMCP trust report for one MCP server: score with per-category verdicts and reasons, the tools it exposes with their context-token cost, and its recent change history. Use before installing or trusting a server. Accepts a package name, endpoint URL, registry name or verifymcp slug.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"component": "npm",
"identifier": "io.github.acme/tools"
},
{
"identifier": "acme-tools"
}
],
"properties": {
"component": {
"description": "Which channel to report on when a server ships several.",
"type": "string"
},
"identifier": {
"description": "Package name, endpoint URL, registry name or verifymcp slug.",
"type": "string"
}
},
"required": [
"identifier"
],
"type": "object"
},
"name": "get_server",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"properties": {
"categories": {
"description": "Per-category breakdown in rubric order.",
"items": {
"additionalProperties": false,
"properties": {
"name": {
"description": "Category name.",
"type": "string"
},
"reasons": {
"description": "Plain-English findings.",
"items": {
"type": "string"
},
"type": "array"
},
"score": {
"description": "Category score; null when pending.",
"type": [
"integer",
"null"
]
},
"verdict": {
"description": "unverified means we could not determine it, NOT that it failed.",
"enum": [
"pass",
"partial",
"fail",
"unverified"
],
"type": "string"
}
},
"required": [
"name",
"score",
"verdict",
"reasons"
],
"type": "object"
},
"type": "array"
},
"changes": {
"additionalProperties": false,
"properties": {
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"direction": {
"description": "Whether this was a step back or forward.",
"enum": [
"regression",
"improvement",
"neutral"
],
"type": "string"
},
"id": {
"description": "Event identifier.",
"type": "string"
},
"kind": {
"description": "Machine-readable event kind, e.g. tool.removed.",
"type": "string"
},
"materiality": {
"description": "How much this change matters.",
"enum": [
"critical",
"security",
"functional",
"cosmetic"
],
"type": "string"
},
"occurredOn": {
"description": "UTC date observed.",
"type": "string"
},
"scoreDelta": {
"description": "Score movement attributed to it.",
"type": [
"integer",
"null"
]
},
"summary": {
"description": "Plain-English description.",
"type": "string"
},
"url": {
"description": "Deep link to the event.",
"type": "string"
}
},
"required": [
"id",
"kind",
"summary",
"materiality",
"direction",
"scoreDelta",
"occurredOn",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"type": "object"
},
"claimed": {
"description": "Owner has proved ownership.",
"type": "boolean"
},
"component": {
"description": "Channel reported on.",
"type": "string"
},
"deletedAt": {
"description": "When the registry removed it.",
"type": [
"string",
"null"
]
},
"description": {
"description": "Publisher summary.",
"type": [
"string",
"null"
]
},
"identifier": {
"description": "Package name or endpoint URL of this channel.",
"type": "string"
},
"inconclusive": {
"description": "Checks we could not complete. Absence of evidence, not evidence of a problem.",
"items": {
"type": "string"
},
"type": "array"
},
"lastScoredAt": {
"description": "When this channel was last scored.",
"type": [
"string",
"null"
]
},
"liveness": {
"description": "Reachability: live, grace, degraded or dead.",
"type": "string"
},
"malware": {
"additionalProperties": false,
"properties": {
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"component": {
"description": "The channel carrying the finding.",
"type": "string"
},
"critical": {
"description": "The vendor's verdict was critical, which hard-zeroes the score.",
"type": "boolean"
},
"identifier": {
"description": "Package name or endpoint URL of that channel.",
"type": "string"
},
"severity": {
"description": "Vendor-reported severity for a non-critical finding; null when none was given.",
"type": [
"string",
"null"
]
},
"type": {
"description": "Ecosystem of that channel.",
"type": "string"
},
"url": {
"description": "Canonical page for the affected channel.",
"type": "string"
}
},
"required": [
"component",
"type",
"identifier",
"critical",
"severity",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"type": "object"
},
"matchedOn": {
"description": "Which form of identifier matched.",
"enum": [
"slug",
"registry_name",
"package",
"remote_url"
],
"type": "string"
},
"name": {
"description": "Display name.",
"type": "string"
},
"products": {
"description": "Product slugs this server is classified as working with. Empty means either classified to nothing or not yet classified; the two are indistinguishable, and classification covers hosted remote endpoints only.",
"items": {
"type": "string"
},
"type": "array"
},
"registryName": {
"description": "Reverse-DNS registry name.",
"type": "string"
},
"registryStatus": {
"description": "active, deprecated or deleted.",
"type": "string"
},
"score": {
"description": "Trust score 0-100; null when never scored.",
"type": [
"integer",
"null"
]
},
"siblingComponents": {
"description": "Other channels of the same server, which may score differently.",
"items": {
"additionalProperties": false,
"properties": {
"component": {
"description": "Channel slug.",
"type": "string"
},
"score": {
"description": "That channel's score.",
"type": [
"integer",
"null"
]
},
"type": {
"description": "Ecosystem.",
"type": "string"
},
"url": {
"description": "Canonical page.",
"type": "string"
}
},
"required": [
"component",
"type",
"score",
"url"
],
"type": "object"
},
"type": "array"
},
"slug": {
"description": "Stable verifymcp identifier.",
"type": "string"
},
"status": {
"description": "Scoring status.",
"type": [
"string",
"null"
]
},
"statusMessage": {
"description": "The registry's stated reason for a deprecated or deleted status, quoted from the publisher. Null when none was given, which is always the case while active.",
"type": [
"string",
"null"
]
},
"tools": {
"additionalProperties": false,
"properties": {
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"description": {
"description": "What the tool does.",
"type": [
"string",
"null"
]
},
"hasExamples": {
"description": "Ships JSON-Schema examples.",
"type": "boolean"
},
"hasOutputSchema": {
"description": "Declares structured output.",
"type": "boolean"
},
"inputs": {
"description": "Input parameters.",
"items": {
"additionalProperties": false,
"properties": {
"description": {
"description": "Parameter documentation, if any.",
"type": [
"string",
"null"
]
},
"name": {
"description": "Parameter name.",
"type": "string"
},
"required": {
"description": "Whether the tool requires this parameter.",
"type": "boolean"
},
"type": {
"description": "JSON scalar type, or null when unspecified.",
"type": [
"string",
"null"
]
}
},
"required": [
"name",
"type",
"required",
"description"
],
"type": "object"
},
"type": "array"
},
"name": {
"description": "Tool name.",
"type": "string"
},
"outputs": {
"description": "Output schema fields.",
"items": {
"additionalProperties": false,
"properties": {
"description": {
"description": "Parameter documentation, if any.",
"type": [
"string",
"null"
]
},
"name": {
"description": "Parameter name.",
"type": "string"
},
"required": {
"description": "Whether the tool requires this parameter.",
"type": "boolean"
},
"type": {
"description": "JSON scalar type, or null when unspecified.",
"type": [
"string",
"null"
]
}
},
"required": [
"name",
"type",
"required",
"description"
],
"type": "object"
},
"type": "array"
},
"title": {
"description": "Human title, when distinct from name.",
"type": [
"string",
"null"
]
},
"tokenEstimate": {
"description": "Approximate context tokens this tool's definition costs.",
"type": "integer"
}
},
"required": [
"name",
"title",
"description",
"inputs",
"outputs",
"hasOutputSchema",
"hasExamples",
"tokenEstimate"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"type": "object"
},
"toolsTruncatedAtCapture": {
"description": "Our capture hit a size bound, so the tool list may be incomplete.",
"type": "boolean"
},
"type": {
"description": "Ecosystem: remote, npm, pypi, oci, nuget or mcpb.",
"type": "string"
},
"url": {
"description": "Canonical verifymcp.io page.",
"type": "string"
}
},
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
},
{
"description": "Other MCP servers doing a similar job to a given one, with their trust scores. Neighbours share a product or publisher namespace; this is not a semantic search.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"identifier": "acme-tools"
}
],
"properties": {
"identifier": {
"description": "Package name, endpoint URL, registry name or verifymcp slug.",
"type": "string"
}
},
"required": [
"identifier"
],
"type": "object"
},
"name": "get_server_alternatives",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"component": {
"description": "The channel url points at; null when it has none.",
"type": [
"string",
"null"
]
},
"name": {
"description": "Display name.",
"type": "string"
},
"reason": {
"description": "Why it is a neighbour: a shared product, or a shared publisher namespace. Not an endorsement.",
"type": "string"
},
"score": {
"description": "Trust score 0-100; null when unscored.",
"type": [
"integer",
"null"
]
},
"slug": {
"description": "Pass to get_server for the full report.",
"type": "string"
},
"status": {
"description": "deprecated, dead and so on; null for a healthy server.",
"type": [
"string",
"null"
]
},
"url": {
"description": "Canonical verifymcp.io page.",
"type": "string"
}
},
"required": [
"slug",
"component",
"name",
"score",
"reason",
"status",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
},
{
"description": "Compare up to 5 MCP servers side by side: trust scores, per-category breakdown, tool counts and context-token cost. Use when choosing between candidates that do the same job. Accepts package names, endpoint URLs, registry names or verifymcp slugs.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{
"identifiers": [
"@acme/mcp-server",
"@other/mcp-server"
]
},
{
"identifiers": [
"acme-tools",
"beta-tools",
"gamma-tools"
]
}
],
"properties": {
"identifiers": {
"description": "Two to 5 servers to compare, as names, URLs or slugs.",
"items": {
"type": "string"
},
"maxItems": 5,
"minItems": 2,
"type": "array"
}
},
"required": [
"identifiers"
],
"type": "object"
},
"name": "get_server_comparison",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"categories": {
"description": "Per-category comparison axes, from the best-scoring channel.",
"items": {
"additionalProperties": false,
"properties": {
"name": {
"description": "Category name.",
"type": "string"
},
"reasons": {
"description": "Plain-English findings.",
"items": {
"type": "string"
},
"type": "array"
},
"score": {
"description": "Category score; null when pending.",
"type": [
"integer",
"null"
]
},
"verdict": {
"description": "unverified means undetermined, NOT failed.",
"enum": [
"pass",
"partial",
"fail",
"unverified"
],
"type": "string"
}
},
"required": [
"name",
"score",
"verdict",
"reasons"
],
"type": "object"
},
"type": "array"
},
"channel": {
"description": "Best-scoring channel, e.g. remote or npm.",
"type": [
"string",
"null"
]
},
"claimed": {
"description": "Owner has proved ownership.",
"type": "boolean"
},
"componentCount": {
"description": "How many channels this server ships.",
"type": [
"integer",
"null"
]
},
"found": {
"description": "False when nothing matched; all other fields are then null.",
"type": "boolean"
},
"identifier": {
"description": "The identifier you supplied, echoed back.",
"type": "string"
},
"lastScoredAt": {
"description": "When the best channel was last scored.",
"type": [
"string",
"null"
]
},
"name": {
"description": "Display name.",
"type": [
"string",
"null"
]
},
"registryStatus": {
"description": "active, deprecated or deleted.",
"type": [
"string",
"null"
]
},
"score": {
"description": "Best trust score 0-100.",
"type": [
"integer",
"null"
]
},
"slug": {
"description": "Resolved verifymcp identifier.",
"type": [
"string",
"null"
]
},
"status": {
"description": "Scoring status.",
"type": [
"string",
"null"
]
},
"tokenFootprint": {
"description": "Approximate context tokens all its tools cost.",
"type": [
"integer",
"null"
]
},
"toolCount": {
"description": "Tools advertised across remote channels.",
"type": [
"integer",
"null"
]
},
"url": {
"description": "Canonical verifymcp.io page.",
"type": [
"string",
"null"
]
}
},
"required": [
"identifier",
"found",
"slug",
"name",
"score",
"status",
"channel",
"componentCount",
"toolCount",
"tokenFootprint",
"lastScoredAt",
"claimed",
"registryStatus",
"categories",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
},
{
"description": "The evidence behind one server's score: TLS, DNSSEC, authorization, redirects, transports, provenance, install scripts, known CVEs and dependency health. Use to explain a low score.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"component": "npm",
"identifier": "io.github.acme/tools"
}
],
"properties": {
"component": {
"description": "Which channel to report on when a server ships several.",
"type": "string"
},
"identifier": {
"description": "Package name, endpoint URL, registry name or verifymcp slug.",
"type": "string"
}
},
"required": [
"identifier"
],
"type": "object"
},
"name": "get_server_diagnostics",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"properties": {
"auth": {
"description": "Authorization posture: the gate, the challenge, and RFC 9728 metadata. Null when not captured.",
"type": [
"object",
"null"
]
},
"captureTruncated": {
"description": "The capture was trimmed to fit its storage bound, so sections may be missing.",
"type": "boolean"
},
"capturedAt": {
"description": "When the probe ran; null when never.",
"type": [
"string",
"null"
]
},
"component": {
"description": "Channel these diagnostics belong to.",
"type": "string"
},
"declaredUrl": {
"description": "The registry-declared URL, when it differs from the one probed.",
"type": [
"string",
"null"
]
},
"dependencies": {
"description": "Dependency-tree counts. `partial` true means the tree did not fully resolve and counts undercount.",
"type": [
"object",
"null"
]
},
"dnssec": {
"description": "The DNSSEC validation walk, root to leaf. Null when not captured.",
"type": [
"object",
"null"
]
},
"endpoint": {
"description": "The URL actually probed, after any redirect.",
"type": [
"string",
"null"
]
},
"installScripts": {
"additionalProperties": false,
"properties": {
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"description": "A lifecycle hook found in the package manifest, with the review tier assigned to it.",
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"type": "object"
},
"provenance": {
"description": "Attestation and signing evidence for a published package. Null when not captured.",
"type": [
"object",
"null"
]
},
"redirect": {
"description": "The plaintext http:// probe behind the HTTPS-enforcement check. Null when not captured.",
"type": [
"object",
"null"
]
},
"slug": {
"description": "Stable verifymcp identifier.",
"type": "string"
},
"tls": {
"description": "Handshake outcome, negotiated version, cipher and certificate chain summaries. Null when not captured.",
"type": [
"object",
"null"
]
},
"track": {
"description": "Which probe produced this: remote or package.",
"type": [
"string",
"null"
]
},
"transports": {
"additionalProperties": false,
"properties": {
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"description": "One transport probe: which was offered and whether we could speak it.",
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"type": "object"
},
"url": {
"description": "Canonical verifymcp.io page.",
"type": "string"
},
"vulnerabilities": {
"additionalProperties": false,
"properties": {
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"description": "A known vulnerability affecting the dependency tree, with its CVE or advisory id.",
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"type": "object"
}
},
"required": [
"slug",
"component",
"capturedAt",
"track",
"endpoint",
"declaredUrl",
"captureTruncated",
"tls",
"dnssec",
"auth",
"redirect",
"transports",
"provenance",
"installScripts",
"vulnerabilities",
"dependencies",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
},
{
"description": "Ready-to-paste install snippets for one MCP server, for every client we support. An MCPB bundle has no launch command, so it returns the download URL, the registry's SHA-256 and commands to verify the file instead. Read get_server first: this returns configuration, not a safety judgement.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"component": "npm",
"identifier": "acme-tools"
}
],
"properties": {
"component": {
"description": "Which channel to report on when a server ships several.",
"type": "string"
},
"identifier": {
"description": "Package name, endpoint URL, registry name or verifymcp slug.",
"type": "string"
}
},
"required": [
"identifier"
],
"type": "object"
},
"name": "get_server_install_config",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"bundle": {
"additionalProperties": false,
"description": "MCPB bundles only (null otherwise): the file to download, the SHA-256 the registry declares for it, and commands that check the download against it. Open the verified file with an MCPB-capable host such as Claude Desktop.",
"properties": {
"fileName": {
"description": "File name the verify commands expect the download to be saved as.",
"type": "string"
},
"sha256": {
"description": "Lowercase hex SHA-256 the registry declares for the file; null when it declares none, so there is nothing to verify against.",
"pattern": "^[0-9a-f]{64}$",
"type": [
"string",
"null"
]
},
"url": {
"description": "Download URL of the .mcpb bundle.",
"format": "uri",
"type": "string"
},
"verify": {
"description": "Commands that check the downloaded file against sha256. Empty when sha256 is null.",
"items": {
"additionalProperties": false,
"properties": {
"body": {
"description": "The command. Use verbatim.",
"type": "string"
},
"id": {
"description": "shasum or powershell.",
"type": "string"
},
"label": {
"description": "Where the command runs.",
"type": "string"
},
"lang": {
"enum": [
"bash",
"powershell"
],
"type": "string"
}
},
"required": [
"id",
"label",
"lang",
"body"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"url",
"sha256",
"fileName",
"verify"
],
"type": [
"object",
"null"
]
},
"context": {
"additionalProperties": false,
"description": "What we know about the server being installed. Present whenever a server resolved, including when no snippets could be built; null only when the identifier matched nothing.",
"properties": {
"claimed": {
"description": "Owner has proved ownership of the listing.",
"type": "boolean"
},
"malwareScan": {
"description": "confirmed: a vendor flagged this server. clean: a vendor assessed it and found nothing. not_scanned: nobody assessed it, which is NOT an all-clear.",
"enum": [
"confirmed",
"clean",
"not_scanned"
],
"type": "string"
},
"publisherClass": {
"description": "official, verified, third_party or unknown. unknown means no proof, not disproof.",
"type": "string"
},
"score": {
"description": "Trust score 0-100; null when never scored.",
"type": [
"integer",
"null"
]
},
"status": {
"description": "Scoring status for this channel.",
"type": [
"string",
"null"
]
},
"url": {
"description": "Canonical page carrying the full report.",
"type": "string"
},
"verdict": {
"description": "Worst category verdict. unverified means we could not determine it, NOT that it failed.",
"enum": [
"pass",
"partial",
"fail",
"unverified"
],
"type": "string"
}
},
"required": [
"score",
"status",
"verdict",
"malwareScan",
"claimed",
"publisherClass",
"url"
],
"type": [
"object",
"null"
]
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"body": {
"description": "The snippet itself. Use verbatim; never re-escape it.",
"type": "string"
},
"client": {
"description": "Client id, e.g. claude, cursor, vscode.",
"type": "string"
},
"comment": {
"description": "Leading comment line, e.g. where the block goes.",
"type": "string"
},
"label": {
"description": "Client display name.",
"type": "string"
},
"lang": {
"description": "Snippet language.",
"enum": [
"bash",
"json",
"toml",
"yaml"
],
"type": "string"
},
"note": {
"description": "Caveat for this client, where the syntax is a convention rather than a guarantee.",
"type": [
"string",
"null"
]
}
},
"required": [
"client",
"label",
"lang",
"comment",
"body",
"note"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source",
"context",
"bundle"
],
"type": "object"
}
},
{
"description": "Every tool one MCP server exposes, with its parameters, output schema and context-token cost. Use when get_server reported the tool list was truncated.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{
"identifier": "@modelcontextprotocol/server-github"
},
{
"identifier": "https://mcp.example.com/mcp"
},
{
"component": "npm",
"identifier": "acme-tools"
}
],
"properties": {
"component": {
"description": "Which channel to report on when a server ships several.",
"type": "string"
},
"identifier": {
"description": "Package name, endpoint URL, registry name or verifymcp slug.",
"type": "string"
}
},
"required": [
"identifier"
],
"type": "object"
},
"name": "get_server_tools",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"component": {
"description": "Channel these tools belong to.",
"type": "string"
},
"slug": {
"description": "Stable verifymcp identifier.",
"type": "string"
},
"tokenFootprint": {
"description": "Total estimated context tokens for every tool listed here.",
"minimum": 0,
"type": "integer"
},
"tools": {
"additionalProperties": false,
"properties": {
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"description": {
"description": "What the tool does.",
"type": [
"string",
"null"
]
},
"hasExamples": {
"description": "Ships JSON-Schema examples.",
"type": "boolean"
},
"hasOutputSchema": {
"description": "Declares structured output.",
"type": "boolean"
},
"inputs": {
"description": "Input parameters.",
"items": {
"additionalProperties": false,
"properties": {
"description": {
"description": "Parameter documentation, if any.",
"type": [
"string",
"null"
]
},
"name": {
"description": "Parameter name.",
"type": "string"
},
"required": {
"description": "Whether the tool requires this parameter.",
"type": "boolean"
},
"type": {
"description": "JSON scalar type, or null when unspecified.",
"type": [
"string",
"null"
]
}
},
"required": [
"name",
"type",
"required",
"description"
],
"type": "object"
},
"type": "array"
},
"name": {
"description": "Tool name.",
"type": "string"
},
"outputs": {
"description": "Output schema fields.",
"items": {
"additionalProperties": false,
"properties": {
"description": {
"description": "Parameter documentation, if any.",
"type": [
"string",
"null"
]
},
"name": {
"description": "Parameter name.",
"type": "string"
},
"required": {
"description": "Whether the tool requires this parameter.",
"type": "boolean"
},
"type": {
"description": "JSON scalar type, or null when unspecified.",
"type": [
"string",
"null"
]
}
},
"required": [
"name",
"type",
"required",
"description"
],
"type": "object"
},
"type": "array"
},
"title": {
"description": "Human title, when distinct from name.",
"type": [
"string",
"null"
]
},
"tokenEstimate": {
"description": "Approximate context tokens this tool's definition costs.",
"type": "integer"
}
},
"required": [
"name",
"title",
"description",
"inputs",
"outputs",
"hasOutputSchema",
"hasExamples",
"tokenEstimate"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice"
],
"type": "object"
},
"truncatedAtCapture": {
"description": "The server itself truncated its tool list when we captured it, so it may expose more.",
"type": "boolean"
},
"url": {
"description": "Canonical verifymcp.io page.",
"type": "string"
}
},
"required": [
"slug",
"component",
"tokenFootprint",
"truncatedAtCapture",
"tools",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
},
{
"description": "List MCP server components carrying a supply-chain malware finding. Use to check whether anything in the register is flagged before installing.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{},
{
"status": "active"
},
{
"status": "all"
}
],
"properties": {
"status": {
"default": "active",
"description": "Which findings to return: active, unverified, cleared or all. Defaults to active.",
"enum": [
"active",
"unverified",
"cleared",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "list_known_malware",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"clearedOn": {
"description": "Cleared rows only: first clean day.",
"type": [
"string",
"null"
]
},
"code": {
"description": "The reason code recorded for the finding.",
"type": "string"
},
"component": {
"description": "The affected channel's slug.",
"type": "string"
},
"critical": {
"description": "Vendor graded it critical, which floors the component's score to zero.",
"type": "boolean"
},
"firstFlaggedOn": {
"description": "UTC day OUR scan first recorded it. Not a vendor detection date; no vendor publishes one.",
"type": "string"
},
"flaggedOnOrBefore": {
"description": "It was already present on the oldest reading we hold, so it began on or before that day.",
"type": "boolean"
},
"lastCheckedOn": {
"description": "Newest day we hold any reading for this component.",
"type": "string"
},
"lastConfirmedOn": {
"description": "Most recent UTC day a finding was confirmed.",
"type": "string"
},
"llmOnly": {
"description": "Every indicator is a model's suspicion with no signature match. Report it as suspicion, never as a detection.",
"type": "boolean"
},
"packageIdentifier": {
"description": "The flagged package.",
"type": "string"
},
"registryDeleted": {
"description": "The registry has since dropped this server.",
"type": "boolean"
},
"registryType": {
"description": "Ecosystem: npm, pypi or nuget.",
"type": "string"
},
"score": {
"description": "The component's trust score; null when never scored.",
"type": [
"integer",
"null"
]
},
"serverName": {
"description": "Display name of the affected server.",
"type": "string"
},
"serverSlug": {
"description": "Pass to get_server for the full report.",
"type": "string"
},
"severity": {
"description": "Vendor severity; null when none was given.",
"type": [
"string",
"null"
]
},
"state": {
"description": "active: still flagged. unverified: the finding was replaced by an inconclusive read. cleared: a later scan came back clean.",
"enum": [
"active",
"unverified",
"cleared"
],
"type": "string"
},
"url": {
"description": "Canonical page carrying the full breakdown.",
"type": "string"
},
"vendor": {
"description": "Which scanner answered.",
"type": "string"
},
"vendorUrl": {
"description": "The vendor's own report, when it indexes this ecosystem.",
"type": [
"string",
"null"
]
},
"versionChecked": {
"description": "Version the verdict pertained to; null when the scan recorded none.",
"type": [
"string",
"null"
]
}
},
"required": [
"serverSlug",
"serverName",
"component",
"registryType",
"packageIdentifier",
"versionChecked",
"state",
"critical",
"severity",
"llmOnly",
"code",
"vendor",
"firstFlaggedOn",
"flaggedOnOrBefore",
"lastConfirmedOn",
"clearedOn",
"lastCheckedOn",
"score",
"registryDeleted",
"url",
"vendorUrl"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
},
{
"description": "List the products MCP servers integrate with, such as github or notion, and how many servers cover each. Use to find the product slug that list_servers accepts.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{},
{
"query": "git"
},
{
"query": "notion"
}
],
"properties": {
"query": {
"description": "Name fragment to match against product names and slugs.",
"maxLength": 100,
"type": "string"
}
},
"type": "object"
},
"name": "list_products",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"name": {
"description": "Product display name.",
"type": "string"
},
"serverCount": {
"description": "Listed servers classified under this product. A floor, not a census: see notice.",
"minimum": 0,
"type": "integer"
},
"slug": {
"description": "The value to pass as list_servers' product filter.",
"type": "string"
},
"tierA": {
"description": "Has an editorial hub page on verifymcp.io.",
"type": "boolean"
},
"url": {
"description": "Hub page, or null when the product has none.",
"type": [
"string",
"null"
]
}
},
"required": [
"slug",
"name",
"tierA",
"serverCount",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
},
{
"description": "Filter the VerifyMCP directory of scored MCP servers. Use to discover servers by name fragment, ecosystem, product or trust score. Name matching only: descriptions and capabilities are not searched, so a plain-English question matches nothing. Returns the first 100.",
"inputSchema": {
"additionalProperties": false,
"examples": [
{
"query": "github"
},
{
"minScore": 70,
"product": "github"
},
{
"minScore": 80,
"sort": "score_desc",
"types": [
"remote"
]
},
{
"scored": "scored",
"types": [
"npm",
"pypi"
]
},
{
"query": "postgres",
"types": [
"npm"
]
}
],
"properties": {
"maxScore": {
"description": "Highest trust score to include.",
"maximum": 100,
"minimum": 0,
"type": "integer"
},
"minScore": {
"description": "Lowest trust score to include.",
"maximum": 100,
"minimum": 0,
"type": "integer"
},
"product": {
"description": "Restrict to servers classified as working with this product, e.g. github.",
"type": "string"
},
"query": {
"description": "Name fragment to match against server and package names.",
"maxLength": 100,
"type": "string"
},
"scored": {
"default": "scored",
"description": "Include unscored servers. Defaults to scored only.",
"enum": [
"scored",
"unscored",
"all"
],
"type": "string"
},
"sort": {
"description": "Default: best match (then trust) with a query, else trust. A given sort is applied exactly.",
"enum": [
"score_desc",
"score_asc",
"name_asc",
"name_desc",
"channels_asc",
"channels_desc"
],
"type": "string"
},
"types": {
"description": "Restrict to these ecosystems; a server matches any one of them.",
"items": {
"enum": [
"remote",
"npm",
"pypi",
"oci",
"nuget",
"mcpb"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "list_servers",
"outputSchema": {
"additionalProperties": false,
"properties": {
"asOf": {
"description": "When this data was read (UTC).",
"format": "date-time",
"type": "string"
},
"count": {
"description": "Number of entries in items.",
"minimum": 0,
"type": "integer"
},
"items": {
"items": {
"additionalProperties": false,
"properties": {
"claimed": {
"description": "Owner has proved ownership of this listing.",
"type": "boolean"
},
"componentTypes": {
"description": "Ecosystems this server ships in.",
"items": {
"type": "string"
},
"type": "array"
},
"description": {
"description": "Publisher-supplied summary.",
"type": [
"string",
"null"
]
},
"liveness": {
"description": "Reachability: live, grace, degraded or dead.",
"type": "string"
},
"name": {
"description": "Human-readable display name.",
"type": "string"
},
"products": {
"description": "Product slugs this server is classified as working with. Empty means either classified to nothing or not yet classified; the two are indistinguishable.",
"items": {
"type": "string"
},
"type": "array"
},
"registryName": {
"description": "Reverse-DNS registry name.",
"type": "string"
},
"registryStatus": {
"description": "Registry lifecycle: active, deprecated or deleted.",
"type": "string"
},
"score": {
"description": "Best trust score 0-100; null when unscored.",
"type": [
"integer",
"null"
]
},
"slug": {
"description": "Stable verifymcp identifier for this server.",
"type": "string"
},
"status": {
"description": "Scoring status for the best component.",
"type": [
"string",
"null"
]
},
"url": {
"description": "Canonical verifymcp.io page for this server.",
"type": "string"
},
"weekDelta": {
"description": "Score movement over the last 7 days.",
"type": [
"integer",
"null"
]
}
},
"required": [
"slug",
"name",
"registryName",
"description",
"score",
"status",
"weekDelta",
"componentTypes",
"products",
"liveness",
"registryStatus",
"claimed",
"url"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
},
"notice": {
"description": "How to narrow a truncated result, or why an empty one is empty; null when neither applies.",
"type": [
"string",
"null"
]
},
"source": {
"description": "Canonical verifymcp.io page for this result.",
"format": "uri",
"type": "string"
},
"total": {
"description": "Matches before the 100-item cap.",
"minimum": 0,
"type": "integer"
},
"truncated": {
"description": "True when total exceeds count.",
"type": "boolean"
}
},
"required": [
"items",
"count",
"total",
"truncated",
"notice",
"asOf",
"source"
],
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:2b4f1ff6dc4556921174b3a908ac237fbbd8b3c169c1113ff1f0eab3bd088920 | sha256sum