Skip to main content

HVTracker MCP

MCP server for checking supply-chain trust before connecting to AI agents, frameworks, or MCP servers.

The hosted remote server is:

{
  "mcpServers": {
    "hvtracker": {
      "url": "https://hvtracker.net/mcp"
    }
  }
}

This repository also provides a local stdio package for clients that prefer package-based installation.

Tools

  • verify_mcp_server: pre-connect trust verdict for an MCP server, package, GitHub repo, or agent name.
  • check_agent_trust: trust profile for a tracked AI agent or framework — incl. runtime capabilities (MCP status, providers, plugin surface, provenance drift) and the URL of its Ed25519-signed trust credential.
  • compare_agents: two agents side by side with an evidence-based verdict and the published compare-page link.
  • search_agents: search the HVTracker registry by name, repo, description, or category.

Local Install

With npm:

npm install -g hvtracker-mcp

With PyPI:

python3 -m pip install hvtracker-mcp

Example MCP client config:

{
  "mcpServers": {
    "hvtracker": {
      "command": "hvtracker-mcp"
    }
  }
}

Development

python3 -m pip install -e ".[dev]"
python3 -m pytest
hvtracker-mcp

Use a different HVTracker base URL while testing:

HVTRACKER_BASE_URL=http://localhost:8080 hvtracker-mcp

Registry Publishing

The official MCP Registry manifest is server.json.

mcp-publisher login github
mcp-publisher publish

In GitHub Actions, run the "Publish MCP Registry" workflow after the npm, PyPI, and GHCR packages for the same version are live.

The server name is:

io.github.YugantM/hvtracker-mcp

Claude Desktop Extension

Tagged releases build an .mcpb bundle for Claude Desktop from manifest.json. To build it locally:

npm ci --omit=dev
npx @anthropic-ai/mcpb@2.1.2 pack

Privacy

HVTracker MCP sends the user-supplied search string or server identifier to https://hvtracker.net to fetch public trust data. It does not require an API key and does not write to user systems. See the HVTracker site for current data and methodology, and see PRIVACY.md for the repository privacy note.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

hvtracker_mcp-0.2.1.tar.gz (8.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

hvtracker_mcp-0.2.1-py3-none-any.whl (7.4 kB view details)

Uploaded Python 3

File details

Details for the file hvtracker_mcp-0.2.1.tar.gz.

File metadata

  • Download URL: hvtracker_mcp-0.2.1.tar.gz
  • Upload date:
  • Size: 8.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for hvtracker_mcp-0.2.1.tar.gz
Algorithm Hash digest
SHA256 f4f2df04d0eab9d62a8990c05a9f90f5a0e2aebd9d23c07ad77325fb8abbf61c
MD5 d9b618a33f103b49af6baaf8e47a31b8
BLAKE2b-256 581f4a386bd9dfdba97933199c6aa7f326b6301e01ed542d0cbe4065b9ad8c86

See more details on using hashes here.

Provenance

The following attestation bundles were made for hvtracker_mcp-0.2.1.tar.gz:

Publisher: publish-pypi.yml on YugantM/hvtracker-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file hvtracker_mcp-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: hvtracker_mcp-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 7.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for hvtracker_mcp-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 f6b3f40124d4e6b86d44ace427205535419abf7309ab5d4345a5b34a9594a6c4
MD5 68a9e55d13e75b10f859cb3fa0862d02
BLAKE2b-256 2af8730c65e5ab17da28fb8e2a8bdb878b2016708f26d22cf90c63c8ea39c0e1

See more details on using hashes here.

Provenance

The following attestation bundles were made for hvtracker_mcp-0.2.1-py3-none-any.whl:

Publisher: publish-pypi.yml on YugantM/hvtracker-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page