Adopt MCP servers on evidence, not on vibes.
Agents are being wired to third-party servers faster than anyone can review them. MCP Trust Index gives platform, security and developer teams a consistent, explainable read on what is maintained, what has gone quiet, and what is worth a closer look — across the whole registry rather than the handful you happened to hear about.
Who this is for
Platform and DevEx teams
Decide which servers to allow into an internal catalogue, and justify the decision with a per-signal breakdown rather than a hunch.
Security and supply chain
See which declared packages carry known advisories, which run install scripts, and which projects have gone quiet — before an agent is wired to them.
Gateway and IDE vendors
Query the index from your own product so your users see maintenance and risk context at the moment they choose a server.
Server publishers
See exactly how your own servers score, what is costing you points, and what a prospective adopter sees when they look you up.
How we approach it
The index is only useful if you can trust what it does not claim as much as what it does. Four commitments shape everything on this site:
Every number is explained
Each score arrives with the signals, the weights and the reasoning that produced it. Nothing is a black box, because a number your own team cannot interrogate is a number they cannot defend in a review.
Maintenance and risk stay separate
An activity score and a supply-chain flag answer different questions. We never merge them into one figure, because doing so would quietly destroy the meaning of both.
Unknowns are labelled, not guessed
A server with no reachable repository is marked unverified rather than scored as though it were abandoned. You always know the difference between a bad signal and a missing one.
Nothing is executed
Today's flags come from published metadata only — no downloading, installing or running of third-party code. Where a limit exists, we state it rather than implying more coverage than we have.
Working with the data
Everything on this site is queryable. The public API returns the same scores, breakdowns and flags the pages render, so you can pull the index into a catalogue, a dashboard or a CI check without scraping HTML.
If you need something the public endpoints do not cover — a bulk export, a private feed, an on-premise arrangement, or coverage of servers outside the public registry — that is a conversation, and one worth having early. Tell us the shape of the problem below.
Talk to us
Tell us what you are trying to solve and we will tell you honestly whether this index helps. No sales sequence.
Scores measure maintenance activity, not security or fitness for a particular purpose. Risk flags are automated observations from public metadata — useful for triage, not a substitute for your own review. Prefer email? Write to contact@klars.ai.