Model Context Protocol / MCP

Model Context Protocol Servers

Protocols & Tool Integration TypeScript Grade C Listed NOASSERTION
63.5/100
Rank #249 of 1308
Compare Model Context Protocol / MCP

How does it stack up against its Protocols & Tool Integration neighbours?

Pick any agent to compare →

Promising trust profile, but some evidence still deserves review.

Open compare tool Suggest correction
Listing state
Listed
Evidence coverage
Grade B · 3/5 signals
Last push
2026-08-20 · 5d ago
Recent change
Rank +3

Is Model Context Protocol / MCP safe? Model Context Protocol / MCP scores 63.5/100 (Grade C), ranked #249 of 1308 tracked open-source AI agent projects, on evidence coverage B (3 of 5 independent signal types). The public evidence: no package-provenance attestation found; OSSF Scorecard rates its supply-chain practices 6.4/10; 78% of recent commits are signed; last pushed 2026-08-20. Every point is earned from checkable signals — never paid placement. How scoring works →

Ranked neighbours in Protocols & Tool Integration

Quick Trust Read

What Would Improve It
Publish package provenance or release attestations for stronger supply-chain evidence.
Recent Changes
2026-08-25
Rank Moved
Rank rose 16 spots (#265 → #249)
2026-08-24
Rank Moved
Rank dropped 18 spots (#247 → #265)
2026-08-22
Rank Moved
Rank rose 13 spots (#261 → #248)
Maintainer Checklist
Raise Scorecard signals Current OSSF Scorecard is 6.4/10. Tighten the weakest checks to improve public safety evidence.
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
89.6
Activity sub-score · out of 100
#23

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade C reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Evidence coverage B is separate — it grades how many independent signal types back the score (3 of 5), so a high score on thin evidence stays visible. Full methodology →

Signals refreshed 2026-08-25 06:08 UTC · Repo last pushed 5 days ago

Rank Trend

2026-08-11 2026-08-25

Activity & Reach

Stars
89.8k
Forks
11.5k
Last Push
2026-08-20
5 days ago
Commits (4 wk)
21?
Downloads (7d)
HN mentions (30d)
2
Open Issues
247
Rank Change
▲16
was #265

Analysis

HVTrust Dimensions vs Protocols & Tool Integration

63.5 / 100 · 100.0% confidence

Model Context Protocol / MCP Protocols & Tool Integration average (58 agents)

Safety / Integrity50% OSSF Scorecard · 30% provenance · 20% signed commits
11.9 / 25
3.4 above avg 8.5
Identity / Provenance60% listing status · 40% build provenance
10.8 / 18
0.9 below avg 11.7
Transparency50% declared license · 50% OSSF Scorecard
13.9 / 17
2.5 above avg 11.4
Maintenance60% last-push freshness · 40% commit activity
14.3 / 20
0.6 above avg 13.7
AdoptionLog-scaled stars · package downloads
11.9 / 20
1.6 above avg 10.3

Activity Inputs

89.6 / 100
StarsRepository reach
29.7 / 30
FreshnessLast push recency
24.3 / 25
ActivityRecent commits
16.7 / 25
CommunityFork signal
18.9 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
6.4 / 10
OpenSSF Scorecard · scanned Aug 24, 2026
Signed Commits
78%
of last 100 commits verified
Binary-Artifacts 10
Branch-Protection 6
CI-Tests 10
CII-Best-Practices 0
Code-Review 6
Contributors 10
Dangerous-Workflow 10
Dependency-Update-Tool 10
Fuzzing 0
License 9
Maintained 10
Packaging 10
Pinned-Dependencies 2
SAST 6
Security-Policy 10
Signed-Releases -1
Token-Permissions 0
Vulnerabilities 0

Is Model Context Protocol / MCP safe?

Model Context Protocol / MCP has a mixed signal profile. Some trust indicators are present, others are missing. Whether it is safe for your use case depends on which gaps matter to you — review the breakdown below before adopting in production.
Does Model Context Protocol / MCP publish package provenance?
No published build provenance is currently detected for Model Context Protocol / MCP. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does Model Context Protocol / MCP have an OpenSSF Scorecard?
Model Context Protocol / MCP has an OpenSSF Scorecard score of 6.4/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is Model Context Protocol / MCP actively maintained?
Actively maintained. The repository was pushed to within the last 5 day(s).
What license does Model Context Protocol / MCP use?
Model Context Protocol / MCP ships under NOASSERTION. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are Model Context Protocol / MCP's commits signed?
78% of the last 100 commits to Model Context Protocol / MCP are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

AI agent surface

MCP, providers, tool surface
Scored in HVTrust

These runtime-trust fields — detected from public repo docs and manifests — contribute a bounded adjustment to this project's HVTrust score alongside supply-chain evidence. The exact values each field can add or subtract are documented in the methodology → Compare this surface across every listed agent in the capability matrix →

MCP Server Support
high confidence
Implemented
Model Context Protocol / MCP appears to expose MCP server capabilities.
Detailed evidence is not shown in the public view.
External Service Dependencies
low confidence
None detected
No clear third-party provider dependency detected.
Credential signal: API keys or service config markers documented.
Tool / Plugin Surface
high confidence
1 tags
Broad capability areas detected.
  • code
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
  • MCP signal live
  • External deps live
  • Tool / plugin surface live
  • Package provenance drift live

Maintain Model Context Protocol / MCP?

For maintainers

HVTrust scores Model Context Protocol / MCP from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

Signal history
Rank 16Score 2HVTrust 1Grade 1
2026-08-25
Rank Moved
Rank rose 16 spots (#265 → #249)
2026-08-24
Rank Moved
Rank dropped 18 spots (#247 → #265)
2026-08-22
Rank Moved
Rank rose 13 spots (#261 → #248)
2026-08-19
Rank Moved
Rank dropped 16 spots (#248 → #264)
2026-08-17
Rank Moved
Rank rose 11 spots (#261 → #250)
2026-08-13
Rank Moved
Rank dropped 18 spots (#231 → #249)
2026-08-12
Rank Moved
Rank rose 14 spots (#245 → #231)
2026-08-08
Rank Moved
Rank dropped 45 spots (#183 → #228)
2026-08-05
Rank Moved
Rank dropped 10 spots (#186 → #196)
2026-07-29
Rank Moved
Rank rose 10 spots (#199 → #189)
2026-07-28
Rank Moved
Rank dropped 10 spots (#189 → #199)
2026-07-26
Rank Moved
Rank rose 14 spots (#202 → #188)
2026-07-14
Rank Moved
Rank dropped 12 spots (#165 → #177)
2026-07-13
Rank Moved
Rank dropped 23 spots (#142 → #165)
2026-07-04
Activity Score Changed
Activity score up 5pts (85 → 90)
2026-06-29
Rank Moved
Rank rose 12 spots (#158 → #146)
2026-06-24
Rank Moved
Rank dropped 11 spots (#145 → #156)
2026-06-04
Grade Changed
Trust grade C → B
2026-05-29
HVTrust Changed
HVTrust up 9.9pts (54.5 → 64.4)
2026-05-28
Activity Score Changed
Activity score up 13pts (73 → 86)

Embed Badge Badge guide for maintainers →

For maintainers
HVTrust 63.5 Grade C
Markdown:
[![HVTrust](https://hvtracker.net/badge/model-context-protocol-mcp.svg)](https://hvtracker.net/agents/model-context-protocol-mcp)
HTML:
<a href="https://hvtracker.net/agents/model-context-protocol-mcp"><img src="https://hvtracker.net/badge/model-context-protocol-mcp.svg" alt="HVTrust"></a>

Other agents in Protocols & Tool Integration

Data sources
GitHub REST API (repo, commits, stars, forks, license) · OpenSSF Scorecard CLI · Algolia HN Search API
Each agent's signals refresh once daily across 6 staggered batches. Methodology v4.3 · Raw JSON