@rekey.dev/mcp
Model Context Protocol server for Rekey — lets Claude Desktop / Cursor / Claude Code introspect a deployment.
Block For Production
trustsnap_a8ef6b6d8151089d.- Utility Coverage
- Trust Confidence
- Tool Surface Design
- Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.
- Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.
- Compare initialize responses between the latest two runs and restore the previous stable behavior.
- No segmented attention signals observed in the current window.
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risk
Security posture
Tool capability & risk inventory
No tool inventory available from the latest validation run.
Write-action governance
Status detail: No write-action governance evidence is available yet.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Action-controls diff
Need at least two validation runs before diffing action controls.
Critical alerts
Compatibility
Client compatibility verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• Not_Assessedtools_list• Not_Assessedtransport_compliance_probe• Not_Assessedstep_up_auth_probe• Not_Assessedconnector_replay_probe• Not_Assessed — Frozen tool snapshots must survive refresh.request_association_probe• Not_Assessed — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• Not_Assessedtools_list• Not_Assessedtransport_compliance_probe• Not_Assessed
Evidence provenance
action_safety_probe• Not_Assessed
Evidence provenance
tool_snapshot_probe• Not_Assessedconnector_replay_probe• Not_Assessed
Client compatibility gate details
Remediation checklist
- Add OAuth-based authentication for remote connector auth.
- Support dynamic client registration (DCR) to simplify connector setup.
- Fix the server so its initialize handshake succeeds.
- Fix the server so tools/list returns successfully.
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Document step-up auth requirements in a connector-friendly way.
Remediation checklist
- Fix the server so initialize succeeds or cleanly requests auth.
- Fix the server so tools/list returns successfully.
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Expose at least one tool.
- Limit the exposed surface to search/fetch-style read tools.
- Configure OAuth for authenticated remote MCP access.
Remediation checklist
- Resolve the active alert: Initialize flow regressed.
- Resolve the active alert: tools/list regressed.
Verdict traces
initialize_regressed• critical • Initialize flow regressedtools_list_regressed• critical • tools/list regressed
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Not client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Not client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Degraded
- frozen_tool_snapshot_refresh: Passes
- request_association: Likely to fail
- remote_transport: Passes
- tool_discovery: Likely to fail
- auth_connect: Likely to fail
- safe_write_review: Degraded
Recommended for
No recommendation profile is available yet.
Evidence
Current trust snapshot
trustsnap_a8ef6b6d8151089dCanonical machine links
Evidence confidence
Latest validation evidence
Failures
probe_noise_resilienceFetched https://www.npmjs.com/robots.txt
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
advanced_capabilities_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
connector_publishability_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
connector_replay_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
determinism_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
initialize |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
interactive_flow_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
oauth_authorization_server |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
oauth_protected_resource |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
official_registry_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
openid_configuration |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
probe_noise_resilience |
Error | 79.3 ms | Fetched https://www.npmjs.com/robots.txt |
prompt_get |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
prompts_list |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
protocol_version_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
provenance_divergence_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
request_association_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
resource_read |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
resources_list |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
schema_divergence_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
server_card |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
session_resume_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
step_up_auth_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
tool_snapshot_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
tools_list |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
transport_compliance_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
utility_coverage_probe |
Not_Assessed | n/a | Not assessed -- robots.txt consent could not be confirmed. |
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"advanced_capabilities_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"connector_publishability_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"connector_replay_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"determinism_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"initialize": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"interactive_flow_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"oauth_authorization_server": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"oauth_protected_resource": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"official_registry_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"openid_configuration": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"probe_noise_resilience": {
"details": {
"consent_error": "robots.txt returned HTTP 403; consent is unknown",
"headers": {
"content-type": "text/html; charset=UTF-8",
"set-cookie": "__cf_bm=4FKzYMq6gL2fZkkMqGe_Tcn7TJX.UKrpkuYQr95RpF8-1786394275.0407596-1.0.1.1-k6DeMQhkSklE71iNA83L3ROgyXhEZetq5FljzZvnxRffdeK.4ElJKipSr75xgcEEvnlZarc.lO_VbLOy9xaMUm8kUFcUTKFS6NVE4RcgyRthiy5ndCbh_wOEFJOUiRns; HttpOnly; SameSite=None; Secure; Path=/; Domain=npmjs.com; Expires=Mon, 10 Aug 2026 21:07:55 GMT",
"strict-transport-security": "max-age=31536000; includeSubDomains; preload"
},
"http_status": 403,
"url": "https://www.npmjs.com/robots.txt",
"validation_disallowed": "unknown"
},
"latency_ms": 79.28,
"status": "error"
},
"prompt_get": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"prompts_list": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"protocol_version_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"provenance_divergence_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"resource_read": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"resources_list": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"schema_divergence_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"server_card": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"session_resume_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"step_up_auth_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"tool_snapshot_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"tools_list": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"transport_compliance_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
},
"utility_coverage_probe": {
"details": {
"reason": "consent_unknown"
},
"latency_ms": null,
"status": "not_assessed"
}
},
"failures": {
"probe_noise_resilience": {
"consent_error": "robots.txt returned HTTP 403; consent is unknown",
"headers": {
"content-type": "text/html; charset=UTF-8",
"set-cookie": "__cf_bm=4FKzYMq6gL2fZkkMqGe_Tcn7TJX.UKrpkuYQr95RpF8-1786394275.0407596-1.0.1.1-k6DeMQhkSklE71iNA83L3ROgyXhEZetq5FljzZvnxRffdeK.4ElJKipSr75xgcEEvnlZarc.lO_VbLOy9xaMUm8kUFcUTKFS6NVE4RcgyRthiy5ndCbh_wOEFJOUiRns; HttpOnly; SameSite=None; Secure; Path=/; Domain=npmjs.com; Expires=Mon, 10 Aug 2026 21:07:55 GMT",
"strict-transport-security": "max-age=31536000; includeSubDomains; preload"
},
"http_status": 403,
"url": "https://www.npmjs.com/robots.txt",
"validation_disallowed": "unknown"
}
},
"remote_url": "https://www.npmjs.com/package/@rekey.dev/mcp",
"server_card_payload": null,
"server_identifier": "npm-rekey.dev/mcp"
}
Known versions
2.0.0-rc.8
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 10, 2026 08:37:55 PM UTC | Unknown | 0.7 | 84.8 ms | 0 |
| Aug 10, 2026 08:37:41 AM UTC | Failing | 0.0 | 280.5 ms | 0 |
| Aug 09, 2026 08:37:32 PM UTC | Failing | 0.0 | 405.7 ms | 0 |
| Aug 09, 2026 08:37:27 AM UTC | Failing | 0.0 | 290.1 ms | 0 |
| Aug 08, 2026 08:37:23 PM UTC | Failing | 0.0 | 282.3 ms | 0 |
| Aug 08, 2026 12:37:20 PM UTC | Failing | 0.0 | 291.2 ms | 0 |
| Aug 08, 2026 08:37:06 AM UTC | Failing | 0.0 | 290.0 ms | 0 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 10, 2026 08:37:55 PM UTC | Unknown | 0.7 | unknown | unknown | 0 | 0 | summary_changed |
| Aug 10, 2026 08:37:41 AM UTC | Failing | 0.0 | unknown | unknown | not fetched | 0 | none |
| Aug 09, 2026 08:37:32 PM UTC | Failing | 0.0 | unknown | unknown | not fetched | 0 | none |
| Aug 09, 2026 08:37:27 AM UTC | Failing | 0.0 | unknown | unknown | not fetched | 0 | none |
| Aug 08, 2026 08:37:23 PM UTC | Failing | 0.0 | unknown | unknown | not fetched | 0 | none |
| Aug 08, 2026 12:37:20 PM UTC | Failing | 0.0 | unknown | unknown | not fetched | 0 | none |
| Aug 08, 2026 08:37:06 AM UTC | Failing | 0.0 | unknown | unknown | not fetched | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 10, 2026 08:37:54 PM UTC | Completed | Unknown | 84.8 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 10, 2026 08:37:41 AM UTC | Completed | Failing | 280.5 ms | |
| Aug 09, 2026 08:37:32 PM UTC | Completed | Failing | 405.7 ms | |
| Aug 09, 2026 08:37:27 AM UTC | Completed | Failing | 290.1 ms | |
| Aug 08, 2026 08:37:22 PM UTC | Completed | Failing | 282.3 ms | |
| Aug 08, 2026 12:37:19 PM UTC | Completed | Failing | 291.2 ms | |
| Aug 08, 2026 08:37:05 AM UTC | Completed | Failing | 290.0 ms | |
Public server reputation
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 10, 2026 08:37:55 PM UTC | Latest validation: unknown | Score 1.2 with status unknown. |
| Aug 10, 2026 08:37:55 PM UTC | Validation summary changed | Summary moved from failing to unknown. |
| Aug 10, 2026 08:37:55 PM UTC | Score changed | Score delta +0.7 versus the previous run. |
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://www.npmjs.com/package/@rekey.dev/mcp
- Docs: none
- Support: none
- Icon: none
- Remote endpoint: https://www.npmjs.com/package/@rekey.dev/mcp
- Server card: none
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Likely to fail |
|
| Read-only fetch flow | Likely to fail |
|
| OAuth-required connect | Degraded |
|
| Safe write flow with confirmation | Likely to fail |
|
Utility coverage
Transport compliance drilldown
Issues: none
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||
Tool snapshot diff & changelog
Need at least two validation runs before building a tool changelog.
Validation diff
Regressed checks: action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe
Improved checks: none
Newly assessed dimensions: none
No longer assessed dimensions: transport_compliance_score
| Component | Previous | Latest | Delta |
|---|---|---|---|
abuse_noise_ratio_score | 0.0 | 1.0 | 1.0 |
connector_replay_score | 0.0 | 1.0 | 1.0 |
error_contract_score | 0.0 | 1.0 | 1.0 |
recovery_semantics_score | 0.0 | 1.0 | 1.0 |
request_association_score | 0.0 | 1.0 | 1.0 |
security_hygiene_score | 1.0 | 0.0 | -1.0 |
session_resume_score | 0.0 | 1.0 | 1.0 |
step_up_auth_score | 0.0 | 1.0 | 1.0 |
Registry & provenance divergence
| Field | Registry | Live server card |
|---|---|---|
| Title | n/a | n/a |
| Version | n/a | n/a |
| Homepage | n/a | n/a |
Active alerts
- Initialize flow regressed (critical)
A client-visible initialize behavior changed for the worse. - tools/list regressed (critical)
Tool discovery became less reliable on the latest run.
Aliases & registry graph
| Identifier | Source | Canonical | Identity evidence | Score |
|---|---|---|---|---|
npm-rekey.dev/mcp |
npm_package_discovery | yes | canonical | n/a |
Alias consolidation
Strong alias identity requires matching remote URL, server-card URL, repository slug, or explicit registry cross-reference; shared provider namespace alone is not identity.
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| No source disagreements detected. | ||
Fix it
Why this score?
Algorithmic score breakdown
3 component(s) not assessed for this run: Transport Compliance, Action Safety, Provenance Divergence
Experimental candidate components
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| Critical | Ensure tools/list succeeds consistently | Tools discovery is the minimum viable contract for most MCP clients and directories. | Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.Playbook
|
| Critical | Make initialize deterministic and client-friendly | If initialize fails or requires undocumented auth, many MCP clients cannot connect. | Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.Playbook
|
| Critical | Respond to initialize flow regressed | A client-visible initialize behavior changed for the worse. | Compare initialize responses between the latest two runs and restore the previous stable behavior. |
| Critical | Respond to tools/list regressed | Tool discovery became less reliable on the latest run. | Compare tool enumeration outputs between runs and remove non-deterministic behavior. |
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Expose /.well-known/oauth-protected-resource | Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. | Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.Playbook
|
| High | Publish OAuth authorization-server metadata | Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. | Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.Playbook
|
| High | Publish a complete server card | Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals. | Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | |
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Raise Access & Protocol score | Connectivity, auth, and transport expectations for common clients. | Tighten auth discovery, session behavior, and transport metadata until remote clients can connect without guesswork. |
| Medium | Raise Adoption & Market score | Adoption clues and public evidence that the server is intended for external use. | Increase external documentation and directory coverage so users can discover and evaluate the server. |
| Medium | Raise Interface Quality score | How well the tool/resource interface communicates and behaves under automation. | Improve schemas, error contracts, and recovery messages so agents can reason about the surface automatically. |
| Medium | Raise Reliability & Trust score | Operational stability, consistency, and trustworthiness over time. | Stabilize behavior over time and reduce failure drift between validation runs. |
| Medium | Raise Security Posture score | How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs. | Reduce destructive, egress, exec, secret, and freeform-input risk across the exposed tool surface.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Harden generic GET handling | Simple probe requests should not surface server instability or noisy failures. | Harden generic GET handlers around the origin of https://www.npmjs.com/package/@rekey.dev/mcp so incidental traffic does not produce noisy failures. |
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
| Low | Publish or reconcile the server in the official MCP registry | Official registry presence improves discovery confidence and cross-source consistency. |
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Utility Coverage | 0/4 | -4.0 |
| Trust Confidence | 0/4 | -4.0 |
| Tool Surface Design | 0/4 | -4.0 |
| Tool Snapshot Churn | 0/4 | -4.0 |
| Tool Namespace Clarity | 0/4 | -4.0 |
| Tool Capability Clarity | 0/4 | -4.0 |
| Task Success | 0/4 | -4.0 |
| Spec Recency | 0/4 | -4.0 |
| SLO Health | 0/4 | -4.0 |
| Session Semantics | 0/4 | -4.0 |
| Security Hygiene | 0/4 | -4.0 |
| Schema Completeness | 0/4 | -4.0 |
Compatibility profiles
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Governance
MCP TrustOps
TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
No successful connection to this endpoint has been observed yet -- install instructions are withheld until initialize succeeds at least once.
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.npm-rekey.dev/mcp.