Skip to main content

attestari-mcp

Attestari's verdict on an npm or PyPI package version, over the Model Context Protocol. The answer is the Attestari lookup API's: the grade, the decision, the confirmed findings by reason code and place, and the methodology version and document hash the decision cites. "Not examined" is its own answer and is never a sign that a package is safe.

Every lookup needs an Attestari API key (the Developer tier and above, https://attestari.ai/pricing#line-2) and is counted as one lookup, as through the API. What is sent is the ecosystem, the package name and the version, and nothing else.

Run it locally

ATTESTARI_API_KEY=att_live_... uvx attestari-mcp

It speaks MCP over standard input and output and opens no port. In an MCP client's configuration:

{
  "mcpServers": {
    "attestari": {
      "command": "uvx",
      "args": ["attestari-mcp"],
      "env": { "ATTESTARI_API_KEY": "att_live_..." }
    }
  }
}

ATTESTARI_API_URL changes the lookup API's address (default https://api.attestari.ai).

Tools

  • lookup_package: one package (ecosystem: npm or pypi; name; version, or none for the latest version examined).
  • lookup_packages: up to 20 packages at once, each counted as one lookup.

Both only read. Each answer says its outcome: graded, not_gradeable (examined, no opinion given), not_a_server (out of scope), not_examined, under_re_examination, refused (the key, the plan or a limit) or unavailable.

What the answer carries from a package

Its name, its version, and the file paths of its findings and capabilities with their line numbers. No excerpt of a package's code or text is passed on: text written by a package's publisher never reaches the agent through this server.

Licence

MIT.

Metadata

Release files for attestari-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for attestari-mcp 0.1.0
File Size Uploaded
attestari_mcp-0.1.0.tar.gz 20.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for attestari-mcp 0.1.0
File Interpreter ABI Platform
attestari_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 36.4 kB

Release files / attestari_mcp-0.1.0.tar.gz

Download URL attestari_mcp-0.1.0.tar.gz
Size 20.5 kB
Tags Source
SHA-256 checksum
How to use checksums
13209fb134a47209cd0c2ccff0c11537b2fc7bc34f1f4eb141b490a1c2ecdfd8
BLAKE2b-256 checksum
How to use checksums
0832e9fa12b0b31ef75ad46d27c723594ea3d1661783544da347fba2c09f3edb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release files / attestari_mcp-0.1.0-py3-none-any.whl

Download URL attestari_mcp-0.1.0-py3-none-any.whl
Size 15.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
25e4fefd763b235bc16e8150ec4710c834cfb88adec98e0a1aba56974867c689
BLAKE2b-256 checksum
How to use checksums
6bee9840658e57173c86622a6038b657fd1319f6742319d1add5d654fff6f5aa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page