// project
VerifyMCP
VerifyMCP gives every server on the official MCP registry an independent 0–100 trust score on a transparent, verifiable rubric — so you can see which MCP servers to trust.
Visit projectVerifyMCP is an independent trust index for Model Context Protocol (MCP) servers. It continuously syncs the official MCP registry and scores each server from 0 to 100 on a transparent, verifiable rubric, so developers and teams can see at a glance which servers are safe to wire into their AI agents.
How servers are scored
Every server gets a single 0–100 score, but how that score is built depends on the type of server. npm-style packages are scored on supply-chain security and provenance/transparency. Remote endpoints are scored on endpoint security, schema quality and AI usability, stability and change management, and capabilities. Within each category, signals are log-weighted so the few things that matter most dominate the result — and critical failures such as known malware, an unpatched critical CVE, or invalid TLS cap a server's score at zero.
Why it matters
The MCP ecosystem is growing fast, and anyone can publish a server to the registry. That makes supply-chain trust a real concern the moment you connect a third-party tool to an AI agent. VerifyMCP is objective-first — it scores only what can be verified — turning a sprawling registry into a ranked signal you can act on instead of guesswork.
Transparent and independent
Scores come from a published rubric rather than vendor self-reporting, and the official registry is re-synced continuously so ratings track each server as it changes. VerifyMCP is built and maintained by Stuart Blackler.