Skip to content

Disclaimer

Last updated 2026-07-11 · Vouchity

Automated, not audited

Trust Scores are computed automatically from public metadata and heuristics — real signals from GitHub, npm and the official MCP registry, combined with a documented scoring formula. A Trust Score is not a manual security audit, a penetration test, or a code review, and it is not a guaranteethat any server is safe, well-behaved, or free of vulnerabilities. Always review a server's source, permissions and maintainers yourself before relying on it in a production agent.

Information only

Vouchity provides Trust Scores and related information for research and general information purposes only. Nothing on this site is security, legal or professional advice, and nothing here is a recommendation to install, or refrain from installing, any particular server.

Accuracy & sources

Signals are sourced from public GitHub and npm metadata and the official MCP registry, and are presented "as is". They can be delayed, incomplete, or wrong, and a server's underlying repository or package can change at any time. A stated score is an estimate of publicly observable signals, not a promise about the server's code or behaviour. We label the source and an "as of" time for every figure and do not fabricate data — where a signal cannot be verified it is excluded from the score, never guessed — but we make no warranty as to accuracy, completeness, or fitness for any purpose.

Limitation of liability

To the fullest extent permitted by law, Vouchity is not liable for any loss or damage arising from your use of, or reliance on, information provided by Vouchity, including any decision to install or not install an MCP server based on its Trust Score.