MarketNow Registry / Security / mcp-helmet
mcp-helmet
Production middleware for MCP servers. Auto transport, content wrapping, health checks, graceful shutdown, auth, rate limiting, structured request logging. Wraps the official Model Context Protocol SD
Install
$ npx -y mcp-helmetInstalling via npx/uvx/npm install executes arbitrary code from the public registry on your machine. This is the install-risk semantic of the MarketNow catalog — verify the publisher before running it.
Adoption evidence: 9 weekly registry downloads.
How MarketNow scored this
Sentinel Index Heuristics — a security-first estimate from public signals:
- Package age and release activity (stale repositories lose points)
- Verified adoption: registry downloads or GitHub stars, not follower counts
- Typosquat distance against the 150 most-installed MCP packages
- Injection markers scanned in the package description
Heuristic, not a guarantee. For verified agent credentials and revocation, see the MarketNow Trust API.
What is mcp-helmet?
Production middleware for MCP servers. Auto transport, content wrapping, health checks, graceful shutdown, auth, rate limiting, structured request logging. Wraps the official Model Context Protocol SD Indexed by MarketNow with trust 60/100 (Runs registry code).
How do I install it?
Run $ npx -y mcp-helmet Installing via npx/uvx/npm install executes arbitrary code from the public registry on your machine. This is the install-risk semantic of the MarketNow catalog — verify the publisher before running it.
What does the trust score mean?
Security-first heuristic over public signals (age, adoption, typosquat distance, injection markers). It is not a popularity ranking and not a guarantee of safety. mcp-helmet scores 60/100.