{"uid":"cap_o6vHiNYESzCiBhogJzj4o","slug":"polygraph-mcp-agent-security-grading-0a40eae9","name":"Polygraph MCP/Agent Security Grading","description":"Independent A-to-F behavioral security grades for MCP servers, agents, and skills, backed by evidence anyone can re-run. Nobody can pay for a grade.","url":"https://www.polygraph.so/api/x402/grade-request","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"email":{"type":"string","description":"Optional email notified when the grade publishes."},"source":{"type":"string","description":"Optional client name for attribution."},"agent_id":{"type":"string","description":"Optional stable identifier for the requesting agent."},"server_ref":{"type":"string","description":"Target to grade: npm ref (npm/@scope/name), github/owner/repo, pypi/name, or an https:// MCP URL."}}},"responseSchema":{"type":"json","example":{"status":"grading","charged":false,"created":true,"requestId":"req_123","statusUrl":"https://www.polygraph.so/api/grade-requests/req_123/status","deadlineAt":"2026-07-18T12:00:00Z"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ZIya6fzBzAXu1Y1Ecyai-","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Submits an MCP server, agent, or AI skill for independent A-to-F behavioral security grading backed by reproducible evidence","exampleAgentPrompt":"Can you submit my MCP server 'github.com/myorg/myserver' to Polygraph for an independent behavioral security grade? I want to get the A-to-F rating and evidence report before I let anyone use it.","exampleUseCases":[{"title":"Vetting a third-party MCP server before adoption","prompt":"Before I integrate that new calendar MCP server into my workflow, can you run it through Polygraph and get me an independent security grade? I want to see the behavioral evidence before I trust it with my data."},{"title":"Auditing an in-house agent for compliance","prompt":"We're about to ship our customer-support agent to production — can you submit it to Polygraph for a behavioral security grade and send me the status URL so I can track the results?"},{"title":"Comparing trust levels of competing AI skills","prompt":"I'm deciding between two AI skills for my pipeline. Can you kick off a Polygraph grading request for the 'summarizer-pro' skill so I can see its A-to-F security rating and evidence before I make a decision?"}],"resultDescription":"Returns a JSON object confirming the grading job was created, with a unique requestId, a statusUrl to poll for results (the actual A-to-F grade and evidence), a deadlineAt timestamp indicating when grading will be complete, and flags for whether a charge was processed and whether the request was successfully created.","failureModes":["Payment failure — insufficient USDC balance causes the request to be rejected before grading begins","Invalid target — if the MCP server or agent identifier cannot be resolved, the request may fail with a validation error","Duplicate submission — submitting the same target may return an existing in-progress grade rather than creating a new one","Timeout — grading is asynchronous; the deadline may pass without a completed grade if the target is unreachable","Service unavailability — polygraph.so API downtime returns a non-200 response with no requestId"],"whenToPreferThis":"Choose this endpoint when you need an independent, evidence-backed behavioral security grade for an MCP server, AI agent, or skill — especially when you cannot trust self-reported safety claims or vendor-provided audits. It is the right choice when compliance, risk management, or due diligence requires reproducible, third-party verification that no party can purchase or game. Prefer this over general vulnerability scanners or code auditors when the subject is an AI tool with behavioral (not just code-level) risks.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:36:00.048Z","isFirstParty":false}