{"uid":"cap_dbm_NikiQEAwcrkrz6ynd","slug":"mcp-server-trust-security-checker-8cb14fa7","name":"MCP Server Trust & Security Checker","description":"MCP SERVER TRUST / SECURITY CHECK: verify BEFORE connecting whether an MCP server is safe to trust — reachability, MCP handshake, HTTPS, advertised tools, risky capabilities (shell/file/exec) and prompt-injection / tool-poisoning signals — returning a 0-100 trust score, verdict (trusted/review/do-not-trust) and findings. Pass ?target=<mcp-url> to check a specific server (defaults to a live demo server).","url":"https://47620.xyz/x/mcp-trust?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"fields":{"type":"string","description":"Optional comma-separated top-level response keys to keep (e.g. \"health,slot,solUsd\"). Omit for the full payload."}},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type","example"],"properties":{"type":{"type":"string","const":"json"},"example":{"type":"object","required":["ok","endpoint"],"properties":{"ok":{"type":"boolean"},"endpoint":{"type":"string"}},"additionalProperties":true}},"additionalProperties":false}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_BiiljtnBAcgu9Xp-OvVy3","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Evaluates an MCP server for safety and trustworthiness by checking reachability, HTTPS, handshake, risky capabilities, and prompt-injection signals, returning a 0-100 trust score and verdict.","exampleAgentPrompt":"Before I connect to that MCP server at https://some-mcp-server.example.com, can you run a trust check on it and tell me its safety score and whether it has any risky capabilities like shell or file access?","exampleUseCases":[{"title":"Pre-connection MCP server safety audit","prompt":"I'm about to add a new MCP server at https://tools.somevendor.ai/mcp to my agent stack — can you check if it's safe, tell me its trust score, and flag any shell, file, or exec capabilities before I connect?"},{"title":"Detecting prompt injection in a third-party MCP tool","prompt":"I found an MCP server at https://open-mcp.untrusted-domain.xyz — can you scan it for prompt-injection and tool-poisoning signals and give me a verdict on whether I should trust it?"},{"title":"Automated vetting of community MCP servers","prompt":"We're evaluating a list of community MCP servers and the first one is https://community-tools.mcp-hub.io — run a security check on it and tell me if it passes HTTPS, completes the MCP handshake, and comes back as trusted or do-not-trust."}],"resultDescription":"Returns a JSON object containing a 0-100 numeric trust score, a verdict string (trusted, review, or do-not-trust), detailed findings covering reachability, HTTPS validation, MCP handshake result, advertised tools inventory, flagged risky capabilities (shell/file/exec), and any detected prompt-injection or tool-poisoning signals.","failureModes":["Target MCP server is unreachable — returns low trust score with reachability failure finding","Target URL is malformed or missing — returns error response","MCP handshake fails — flagged in findings with reduced trust score","Payment not included or insufficient — x402 payment required error","Rate limiting or timeout on slow target servers — may return partial findings"],"whenToPreferThis":"Use this endpoint when an AI agent or developer needs to vet an MCP server before connecting to it, especially for third-party or community servers where trustworthiness is unknown. It is the right choice when you need a structured, machine-readable trust verdict with specific risk signals (shell access, prompt injection) rather than a manual or ad-hoc review.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T00:47:03.067Z","isFirstParty":false,"canonicalSlug":"mcp-server-trust-security-checker-8cb14fa7"}