The public security memory for MCP packages

Scan a package, inspect a repo dossier, follow advisories, and use the gate in CI when you want enforcement.

Try: mcp-trust-guard, @modelcontextprotocol/server-filesystem, or any npm package

Need repo-level context instead of a one-off package scan?Preview a GitHub repo →Browse tracked dossiers

Inspect. Track. Enforce.

1

Inspect

Check any npm package or public GitHub repo. See scores, findings, publisher posture, repo exposure, and what capabilities the MCP stack grants to an agent.

Free. Instant. No signup.

2

Track

Follow scan history, public advisories, ruleset changes, and maintainer response loops. We monitor 1,160 MCP packages continuously and keep the evidence trail public.

Research, dossiers, and RSS stay public. Package watch email is optional.

3

Enforce

Put the gate in CI. Every PR shows what AI capabilities each MCP package grants. Block unapproved powers. Track approvals with expiry. No API key needed.

See the Policy Gate →

Redis pinned every MCP dependency in RedisInsight after our scan. Agions shipped fixes to taskflow-ai within 48h of our report. HomenShum turned a false-positive report into a same-day scanner improvement.

1,160
packages monitored
13,318
scans on record
3
public maintainer response case studies

See a repo dossier before you install anything

Paste any GitHub repo URL to see its MCP dependencies, capability surface, and what the gate would do. No install needed.

Need enforcement, not just intelligence?

Start with the Policy Gate if you need CI enforcement, repo memory, exceptions, and repo-specific alerts. The scanner, dossiers, and advisory feed stay useful even if you never install the gate.

Open Policy Gate

AgentScore is a public MCP security memory: scanner, package reports, repo dossiers, advisories, and change tracking, with an optional policy gate for CI enforcement. Static analysis plus continuous change detection. Does not inspect runtime behavior or network traffic. Scores are screening signals, not guarantees.