arcade-mcp

MCP Server Framework and Tool Development library for building custom capabilities into agents.

Protocols & Tool Integration Python Grade C Listed MIT
64.8/100
Rank #464 of 1328
Compare arcade-mcp

Promising trust profile, but some evidence still deserves review.

Open compare tool Suggest correction
Listing state
Listed
Evidence coverage
Grade C · 2/5 signals
Last push
2026-09-19 · 1d ago
Recent change
Rank

Is arcade-mcp safe? arcade-mcp scores 64.8/100 (Grade C), ranked #464 of 1328 tracked open-source AI agent projects, on evidence coverage C (2 of 5 independent signal types). The public evidence: no package-provenance attestation found; OSSF Scorecard rates its supply-chain practices 7.4/10; 100% of recent commits are signed; last pushed 2026-09-19. Every point is earned from checkable signals — never paid placement. How scoring works →

Ranked neighbours in Protocols & Tool Integration

Quick Trust Read

What Would Improve It
Publish package provenance or release attestations for stronger supply-chain evidence.
Recent Changes
2026-09-14
Rank Moved
Rank rose 10 spots (#473 → #463)
2026-09-12
Grade Changed
Trust grade B → C
2026-09-12
Rank Moved
Rank dropped 21 spots (#446 → #467)
Maintainer Checklist
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
66.1
Activity sub-score · out of 100
#25

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade C reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage C is separate — it grades how many independent signal types back the score (2 of 5), so a high score on thin evidence stays visible. Full methodology →

Signals refreshed 2026-09-20 21:32 UTC · Repo last pushed yesterday

Rank Trend

2026-08-11 2026-09-20

Activity & Reach

Stars
1.0k
Forks
113
Last Push
2026-09-19
yesterday
Commits (4 wk)
11
Downloads (7d)
HN mentions (30d)
Open Issues
11
Rank Change
▲1
was #465

Analysis

HVTrust Dimensions vs Protocols & Tool Integration

64.8 / 100 · 100.0% confidence

arcade-mcp Protocols & Tool Integration average (61 agents)

Safety / Integrity50% OSSF Scorecard · 30% provenance · 20% signed commits
14.3 / 25
3.8 above avg 10.5
Identity / Provenance60% listing status · 40% build provenance
10.8 / 18
0.8 below avg 11.6
Transparency50% declared license · 50% OSSF Scorecard
14.8 / 17
2.0 above avg 12.8
Maintenance60% last-push freshness · 40% commit activity
16.2 / 20
2.2 above avg 14.0
AdoptionLog-scaled stars · package downloads
7.2 / 20
3.4 below avg 10.6

Activity Inputs

66.1 / 100
StarsRepository reach
18.1 / 30
FreshnessLast push recency
24.9 / 25
ActivityRecent commits
13.5 / 25
CommunityFork signal
9.6 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
7.4 / 10
OpenSSF Scorecard · scanned Sep 20, 2026
Signed Commits
100%
of last 100 commits verified
Binary-Artifacts 10
Branch-Protection 8
CI-Tests 10
CII-Best-Practices 0
Code-Review 10
Contributors 10
Dangerous-Workflow 10
Dependency-Update-Tool 10
Fuzzing 0
License 10
Maintained 10
Packaging 10
Pinned-Dependencies 3
SAST 0
Security-Policy 9
Signed-Releases -1
Token-Permissions 0
Vulnerabilities 10

Is arcade-mcp safe?

arcade-mcp has a mixed signal profile. Some trust indicators are present, others are missing. Whether it is safe for your use case depends on which gaps matter to you — review the breakdown below before adopting in production.
Does arcade-mcp publish package provenance?
No published build provenance is currently detected for arcade-mcp. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does arcade-mcp have an OpenSSF Scorecard?
arcade-mcp has an OpenSSF Scorecard score of 7.4/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is arcade-mcp actively maintained?
Actively maintained. The repository was pushed to within the last 1 day(s).
What license does arcade-mcp use?
arcade-mcp ships under MIT. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are arcade-mcp's commits signed?
100% of the last 100 commits to arcade-mcp are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

AI agent surface

MCP, providers, tool surface
Scored in HVTrust

These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →

MCP Server Support
high confidence
Implemented
arcade-mcp appears to expose MCP server capabilities.
Detailed evidence is not shown in the public view.
External Service Dependencies
high confidence
2 detected
Public provider/service dependencies detected.
Credential signal: No explicit API-key/config marker detected.
Tool / Plugin Surface
None detected
No clear plugin system or broad tool surface detected.
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
  • MCP signal live
  • External deps live
  • Tool / plugin surface live
  • Package provenance drift live
How this surface has changed

Detected changes to arcade-mcp's runtime surface and supply-chain posture, from daily public-signal snapshots. A change here means our detectors see something different — a genuinely changed capability, or better evidence of an existing one.

2026-08-12
Tool Surface Changed
Detected tool/plugin surface changed: declared → none

Maintain arcade-mcp?

For maintainers

HVTrust scores arcade-mcp from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

Signal history
Rank 17Grade 5Listed 1Surface 1HVTrust 1Scorecard 1
2026-09-14
Rank Moved
Rank rose 10 spots (#473 → #463)
2026-09-12
Grade Changed
Trust grade B → C
2026-09-12
Rank Moved
Rank dropped 21 spots (#446 → #467)
2026-09-10
Rank Moved
Rank dropped 10 spots (#427 → #437)
2026-09-08
Grade Changed
Trust grade C → B
2026-09-07
Rank Moved
Rank dropped 27 spots (#405 → #432)
2026-09-06
Grade Changed
Trust grade B → C
2026-09-06
Rank Moved
Rank dropped 12 spots (#393 → #405)
2026-09-05
Rank Moved
Rank dropped 64 spots (#329 → #393)
2026-09-04
Rank Moved
Rank dropped 11 spots (#318 → #329)
2026-09-03
Grade Changed
Trust grade C → B
2026-09-03
Rank Moved
Rank rose 38 spots (#356 → #318)
2026-08-31
Rank Moved
Rank dropped 26 spots (#321 → #347)
2026-08-30
Rank Moved
Rank rose 11 spots (#332 → #321)
2026-08-26
Scorecard Added
OSSF Scorecard: 7.4/10
2026-08-26
Grade Changed
Trust grade D → C
2026-08-26
Rank Moved
Rank rose 547 spots (#866 → #319)
2026-08-26
HVTrust Changed
HVTrust up 38.1pts (24.1 → 62.2)
2026-08-22
Rank Moved
Rank rose 11 spots (#868 → #857)
2026-08-19
Rank Moved
Rank dropped 10 spots (#865 → #875)
2026-08-16
Rank Moved
Rank dropped 20 spots (#851 → #871)
2026-08-12
Tool Surface Changed
Detected tool/plugin surface changed: declared → none
2026-08-12
Rank Moved
Rank rose 40 spots (#899 → #859)
2026-08-10
Rank Moved
Rank dropped 40 spots (#848 → #888)
2026-08-08
Rank Moved
Rank dropped 330 spots (#481 → #811)
2026-08-06
Newly Listed
First tracked at rank #501

Embed Badge Badge guide for maintainers →

For maintainers
HVTrust 64.8 Grade C
Markdown:
[![HVTrust](https://hvtracker.net/badge/arcade-mcp.svg)](https://hvtracker.net/agents/arcade-mcp)
HTML:
<a href="https://hvtracker.net/agents/arcade-mcp"><img src="https://hvtracker.net/badge/arcade-mcp.svg" alt="HVTrust"></a>

Other agents in Protocols & Tool Integration

Data sources
GitHub REST API (repo, commits, stars, forks, license) · OpenSSF Scorecard CLI
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.3 · Raw JSON