{"name":"io.github.joeyough/mcpcheck","slug":"joeyough-mcpcheck","title":null,"description":"Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.","url":"https://mcp.market/server/joeyough-mcpcheck","rating":null,"grade":"C","score":67,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":8,"stars":null,"forks":null,"downloads_week":null,"last_push_at":null,"license":null},"uptime":{"percent":100,"checks":7,"ok":7,"last_checked_at":"2026-09-21T04:10:43.472Z","last_ok_at":"2026-09-21T04:10:43.472Z","latency_ms":344},"claimed":false,"transport":"remote","callable_via_gateway":true,"default_price_micros":0,"repository":"https://github.com/joeyough/mcpcheck","website":"https://mcpcheck.netlify.app","version":"1.0.1","remotes":[{"type":"streamable-http","url":"https://mcpcheck.netlify.app/mcp"}],"packages":[],"tools":[{"name":"check_mcp_trust","description":"Check if an MCP server is safe to install: returns a trust score (0-100, grade A-F). Accepts a registry name (io.github.x/y), a GitHub repo (owner/repo), or a remote MCP URL. For remote servers it live-connects and analyzes the actual exposed tools for tool-poisoning + capabilities, and checks the backing repo (maintenance, license, security policy, auth). Call BEFORE installing or recommending any MCP server.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"target":{"type":"string","description":"Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."}},"required":["target"]}},{"name":"scan_mcp_server","description":"Scan and inspect an MCP server for security issues before connecting it: live tool-poisoning analysis, exposed-tool inventory + capabilities, TLS, and repo trust signals. Same engine as check_mcp_trust. Accepts a registry name, GitHub repo, or remote MCP URL.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"target":{"type":"string","description":"Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."}},"required":["target"]}}],"scan":{"score":67,"grade":"C","scanned_at":"2026-09-21T05:08:56.128Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-21T05:08:56.144Z","components":{"code":{"score":-1,"max":25,"notes":["remote-only server, no package to scan"]},"reliability":{"score":20,"max":20,"notes":["remote reachable in 598ms"]},"poisoning":{"score":15,"max":15,"notes":["2 tool descriptions checked"]},"auth":{"score":10,"max":15,"notes":["open endpoint, read-only tools"]},"maintenance":{"score":3,"max":15,"notes":["repository not readable: repo not found"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[],"inputs":{"probes":[{"url":"https://mcpcheck.netlify.app/mcp","reachable":true,"authRequired":false,"latencyMs":598,"serverInfo":{"name":"mcpcheck","version":"1.0.0"}}],"packages":[],"repo":{"found":false,"owner":"joeyough","repo":"mcpcheck","error":"repo not found"},"icon":{"url":null,"source":"none"},"presence":{"stars":null,"forks":null,"downloadsWeek":null,"license":null,"lastPushAt":null,"score":8}}}},"grade_history":[],"reviews":[]}