An open, reproducible framework for evaluating AI artifacts — skills, MCP servers, agents and plugins. Reads what is inside them, optionally runs them in a sandbox and judges what they did, and publis
An open, reproducible framework for evaluating AI artifacts skills · MCP servers · agents · plugins
Every registry that distributes AI artifacts answers "where did this come from?" None answers "what does it actually do?" as a published, auditable signal.
Assay answers the second question. It reads what is inside an artifact, and optionally runs it in a sandbox with a real model and judges what it did — then publishes a report that somebody who does not trust you can check.
- Why · Install · Quickstart - What you point it at · Reading the output - Running the artifact · In CI · Signing and verifying - How it works · Writing a check · Library use - What Assay does not claim
The gap is not an oversight. The official MCP Registry states in writing that consumers should "assume minimal-to-no moderation," and that it will not remove "low-quality or buggy servers" or "servers with security vulnerabilities." It relies instead on "upstream package registries (like NPM, PyPI, and Docker) or downstream subregistries."
Meanwhile every trust layer the industry does rely on has a dated counterexample:
Layer Counterexample ------------------- --------------------------------------------------------------------------------------------------------------------------------------------------------- Provenance postmark-mcp shipped 15 clean versions, then v1.0.16 added one line BCC'ing every email to an attacker. 1,643 downloads before removal.[^postmark] Reputation The SmartLoader campaign built five fake GitHub accounts cross-forking each other to manufacture a community around a trojan
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/metahub-ai--assay.html)
Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.
naseridev/orvenMCP-compatible context and memory system: paged code navigation for AI assistants, plus a recorded, verified theory of what is known about the code.
ZoeLinUTS/MagicTeX-mcpMagicTeX — a LaTeX editor for AI agents (Claude Code): live PDF preview, PDF comments that drive edits, Visual (WYSIWYG) mode, and git-tracked history. No local TeX install.
dhavanikgithub/chartbrew-mcpChartbrew + AI agents. MCP server exposing Chartbrew's documented API: teams, connections, datasets, dashboards, charts, live queries, and secure embedding. TypeScript · stdio · restricted/unrestricte
livetennisapi/livetennisapi-mcpMCP server for the Live Tennis API — give Claude, Cursor and other LLM agents real-time tennis scores, odds and model win-probability
alexpilotto/uxon-aiMCP server and Claude skills for PPC landing pages, A/B experiments, and first-party conversion tracking. Build Google Ads and Meta pages, run cross-domain experiments, and pull CRO reports via the UX
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.