📡 MCP Radar

illiahaidar/mcptrustchecker

MCP security scanner — offline, deterministic A–F Trust Score for Model Context Protocol servers. Detects tool poisoning, prompt injection & toxic flows.

52 stars
0 forks
TypeScript
momentum ▲ 104.0
created 2026-07-13
on radar since 2026-07-15
star trend 27 → 52 since 2026-07-15
aiartificial-intelligencemcpmcp-protocolmcp-securitymcp-serversmcp-toolsmodel-context-protocolmodelcontextprotocolprompt-injectionsupply-chain-security
View on GitHub ↗Homepage ↗

About mcptrustchecker

The local-first, deterministic security scanner for MCP servers

Know whether a Model Context Protocol server is safe before you connect it to your data.

· offline · deterministic · no account · OAuth browser login for protected servers · one novel core ·

The Capability-Flow Trust Model (methodology mcptrustchecker-1.0) is an original algorithm designed from scratch for this project by Illia Haidar — it is not a wrapper around, or derivative of, any existing scanner or methodology. It is named, versioned, fully specified in docs/methodology.md, and citable via CITATION.cff.

MCP Trust Checker scores an MCP server the way an attacker reasons about it — not as a bag of regex hits, but as a Capability-Flow Trust Model. Every tool is reduced to the roles it can actually play — untrusted-input ingress, sensitive-data source, external / exec sink — derived from behavior, never from the server's own (attacker-controllable) annotations. Those roles are wired into a cross-tool toxic-flow graph that hunts the lethal trifecta: the moment untrusted content, private data, and an exfiltration path co-exist in one agent session — whether inside a single tool or composed across several tools plus the client's built-ins. That is the exact shape behind real-world MCP data-exfiltration exploits, and MCP Trust Checker proves the primitive exists statically, with an honest confidence split so a single-tool completion reads confirmed and a cross-tool composition reads strong — never overclaiming.

From the project README.

Maintaining this server?

Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:

[![On MCP Radar](https://mcp.liqiwa.com/badge.svg)](https://mcp.liqiwa.com/s/illiahaidar--mcptrustchecker.html)

Related MCP servers

12122J/mcpvet

MCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads

⭐ 10JavaScript
mkpoli/gmail-mcp

Multi-account Gmail MCP server on Cloudflare Workers — one deployment, one Google sign-in per connection, any MCP client

⭐ 5TypeScript
qfoldit/UNITY-TOOLBELT

102 composite editor-automation tools for Unity, exposed to AI agents through Unity's own official MCP bridge.

⭐ 5C#
gdbarros94/mcpalace

O Palácio da Memória para Inteligência Artificial

⭐ 3Lua
0xwilliamortiz/openclaude-improved

runs anywhere. uses anything

⭐ 563TypeScript
flankerhqd/cyvisguard

Security control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.

⭐ 30TypeScript

📬 Get the weekly radar in your inbox

The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.