For teams

Adopt MCP servers on evidence, not on vibes.

Agents are being wired to third-party servers faster than anyone can review them. MCP Trust Index gives platform, security and developer teams a consistent, explainable read on what is maintained, what has gone quiet, and what is worth a closer look — across the whole registry rather than the handful you happened to hear about.

0
servers tracked
5
scored signals, all published
9
risk flag types
Weekly
full refresh

Who this is for

Platform and DevEx teams

Decide which servers to allow into an internal catalogue, and justify the decision with a per-signal breakdown rather than a hunch.

Security and supply chain

See which declared packages carry known advisories, which run install scripts, and which projects have gone quiet — before an agent is wired to them.

Gateway and IDE vendors

Query the index from your own product so your users see maintenance and risk context at the moment they choose a server.

Server publishers

See exactly how your own servers score, what is costing you points, and what a prospective adopter sees when they look you up.

How we approach it

The index is only useful if you can trust what it does not claim as much as what it does. Four commitments shape everything on this site:

Every number is explained

Each score arrives with the signals, the weights and the reasoning that produced it. Nothing is a black box, because a number your own team cannot interrogate is a number they cannot defend in a review.

Maintenance and risk stay separate

An activity score and a supply-chain flag answer different questions. We never merge them into one figure, because doing so would quietly destroy the meaning of both.

Unknowns are labelled, not guessed

A server with no reachable repository is marked unverified rather than scored as though it were abandoned. You always know the difference between a bad signal and a missing one.

Nothing is executed

Today's flags come from published metadata only — no downloading, installing or running of third-party code. Where a limit exists, we state it rather than implying more coverage than we have.

Working with the data

Everything on this site is queryable. The public API returns the same scores, breakdowns and flags the pages render, so you can pull the index into a catalogue, a dashboard or a CI check without scraping HTML.

If you need something the public endpoints do not cover — a bulk export, a private feed, an on-premise arrangement, or coverage of servers outside the public registry — that is a conversation, and one worth having early. Tell us the shape of the problem below.

Read the methodology API documentation

Talk to us

Tell us what you are trying to solve and we will tell you honestly whether this index helps. No sales sequence.

Scores measure maintenance activity, not security or fitness for a particular purpose. Risk flags are automated observations from public metadata — useful for triage, not a substitute for your own review. Prefer email? Write to contact@klars.ai.