Attest MCP server
Decide by policy, gate behind a human, verify by read-back, record a hash-chained ledger.
B83/100grade B
Adoption
New
0 stars
Reviews
Write oneNobody has reviewed Attest yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Attest tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.8 · 2026-09-19 · same rubric, same numbers if you re-run it
no findings
- Code scan125 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 83/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Grade history
- 2026-09-19restoreC → Bscore 83
Install directly
claude mcp add attest -- uvx attestlayer
Attest: common questions
- Is Attest MCP server safe?
- Mostly: it is graded B (83/100). Read the Attest safety report
- How do I install Attest?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Attest need an API key?
- Yes. The registry entry asks for
GMAIL_TOKEN,GOOGLE_TOKEN,SLACK_BOT_TOKEN,HUBSPOT_TOKENand 3 more. - Is Attest maintained?
- The last commit was in the last day (2026-09-19). The latest release is v0.1.0.
- What can I use instead of Attest?
- Servers from other publishers that do the same job: Dashclaw MCP server.
Alternatives to Attest
Same job from other publishers: the closest match first, then the best rated.
- DashclawPolicy checks, approvals, records, and governed HTTP capabilities for unattended agents.not reviewedEstablishedB