MCP Server Directory — certified, not just listed

Every entry carries provenance, an install-risk model and an evidence-based trust score. Top packages are deep-scanned against the 29 Sentinel security rules — we publish the raw findings. That is the difference vs popularity-scored directories.

total tracked (deduped)
core · index-certified
community · indexed
deep-scanned (L2)

How certification works

L1Index-certified — every entry

10 documented checks per entry: unique id/slug, resolvable provenance, consistent install-risk model (npx/uvx = red, source/remote = yellow, verified chain = green) and scoring bounds. Live report: /api/certification.

L2Sentinel deep-scan — top artifacts

The shipped registry tarball (shasum-verified) is scanned with the 29 MarketNow rules in tarball mode — including dist/, the code that actually runs. Raw findings published: certification-scans.json.

L3Trust chain — ecosystem

Agent Trust Cards with OCSP/CRL revocation and tool fingerprints (TFP-1.0). Verify any card: /api/atc, revocation list: /api/crl.

Tiers: core = evidence-gated (adoption, verification or age) · community = indexed with weak signal (trust capped at 55) · tracker = inventory of the wider ecosystem (no trust claims — names observed in public directories, deduplicated against our certified core). Owners: claim your badge at /api/badge/<slug>.svg.