A quarter of MCP servers authenticate with a long-lived static secret, and a quarter publish no source at all
The official MCP registry certifies who owns a namespace — in its own words, not code security, not honest tool descriptions, not correct permissions, not unchanged runtime behaviour. So every week we score what each publisher actually declares, ask nobody's permission, and publish the result. Scores and badges are free; there is nothing to sign up for.
Every check, and what failing it means
Each check is decided from the publisher's own registry manifest. Nothing is fetched, nothing is executed, and a check that cannot apply — pinning a package on a server that ships no package — is dropped from that server's total rather than counted against it.
A clean scan earns a badge the publisher never asked for
Every scored server has a verify page at a permanent URL and a signed claim: an in-toto statement signed with Ed25519, bound to the hash of the registry manifest that was scanned. The badge image is only a pointer to it. The default is a pinned badge — two files you commit to your own repo, so your README fetches nothing from us and every change is a commit you review. Anyone can check the claim offline with atpp verify. A scan expires after seven days.
.atpp/badge.svg · attestation.dsse.json
Servers from the latest scan that passed every applicable check:
One repository, declared as the source by thousands of unrelated servers
A server passes source-published by naming a repository. Nothing checks that the publisher owns it, or that the code there is the server — so the same repository turns up as the declared source for listing after listing, and some servers name a repository belonging to an entirely different account. Counted from the latest scan; every row is a link, so you can check it yourself.
What this score does not claim
A level-1 score is a static claim about a published manifest at a point in time. It does not say the code is safe, that the tool descriptions are honest, or that the server behaves at runtime the way it behaves under scan — nobody can say that from a registry listing. Proving what an agent actually did needs a scoped identity and a signed action log, which is Agentic Trust & Protection Platform itself: level 2 (verified) and level 3 (attested) are earned by the consuming company running agents, not by a publisher.
If you publish a server and a check reads wrong, the manifest is the input — fix the listing and the next scan picks it up. The badge charter is the full set of rules we hold ourselves to.