About
Vouchity reads the registry so you don't have to.
The Model Context Protocol made it trivial to wire a new tool into an agent — and just as trivial to wire in one that's abandoned, over-permissioned, or actively malicious. Thousands of MCP servers are published with no vetting process at all. A developer, or an agent choosing its own tools, has no fast way to tell which ones are safe.
Vouchity fixes that. We continuously pull every server from the official MCP registry, enrich it with real signals from GitHub and npm, and compute a transparent Trust Score — so the question "can I install this?" has a sourced, evidence-backed answer instead of a guess.
What we believe
- A score beats a hunch. One calibrated Trust Score tells you more than a star count or a README.
- Every number shows its evidence. Each signal cites the concrete fact it was computed from — a license, a last-publish date, a permissions declaration. Nothing is fabricated; what can't be verified is excluded, never guessed.
- Independent by design. Vouchity isn't a registry, a package host, or a server author — we only score what's already public.
- Built for the agentic web. When a person or an AI asks "is this MCP server safe to install?", the answer should be one sourced score — reachable by a browser or an API call.
The name
To vouch for something is to stake your word on its trustworthiness. The -ity suffix turns a quality into a measurable state — the way authentic becomes authenticity. Vouchityis meant to be exactly that: a measurable, evidence-backed state of trust for every MCP server before it reaches your agent's toolbelt.
Where the data comes from
Today Vouchity sources server metadata from the official MCP registry and enriches it with public GitHub and npm signals, and is built to add more sources over time. Read the full methodology for exactly how each Trust Score is produced.
How it works, in one paragraph
Vouchityre-syncs the official MCP registry on a regular schedule, then enriches every listing with real signals pulled from its linked GitHub repository and npm package: when it last shipped, whether it declares a license, how many people actually use it, whether a remote server requires authentication, and whether its tool descriptions carry patterns associated with prompt injection. Those signals are combined into a 0–100 Trust Score across five weighted categories — maintenance, adoption, transparency, security and provenance — and rolled up into a letter grade. Nothing in that pipeline is manual, and nothing in it is guessed: where a signal can't be verified, it's excluded from the score rather than estimated. See how it works for the full walkthrough, or the methodology for the exact formula and weights.
Right now that pipeline covers 320 servers across 11 categories — search & web is the largest single category — with an average Trust Score of 63/100 and 85 servers (27%) currently graded D or F. Browse the full breakdown on the leaderboard or the risk watch.
Who it's for
- Developerswiring MCP servers into an agent, IDE or automation, who want a fast, sourced answer to "can I install this?" instead of reading a README and hoping.
- Security and platform teamswho need visibility into which MCP servers are already connected across their organization, and a consistent bar for what's allowed to be — see MCP governance for enterprises.
- Agents themselves, via Vouchity's own hosted MCP endpoint, which lets an agent check a server's Trust Score before it ever calls one of its tools.
What Vouchity isn't
Vouchityisn't a package registry, a hosting provider, or a marketplace — it doesn't publish, host or sell MCP servers, and it never will, because the moment a scorer also sells what it's scoring, the score stops being independent. It also isn't a manual security audit: a Trust Score is a fast, evidence-backed read of public signals, not a substitute for reviewing a server's source yourself before trusting it with something that matters. Read the full disclaimer for exactly where that line sits.
Vet your next MCP server in seconds.
Browse every Trust Score free. Create an account to watch the servers you depend on and get a weekly digest. Upgrade any time for alerts and API access.