Skip to main content

mcp-vet

A trust-scan framework for MCP servers: evidence-backed verdicts before you install — usable from any harness.

uvx --from mcp-vetting mcp-vet @modelcontextprotocol/server-fetch   # one command
uvx --from mcp-vetting mcp-vet ./my-server --harness hermes          # verdict + config for YOUR harness
uvx --from mcp-vetting mcp-vet pypi:fastmcp --json --gate            # machine-readable, CI-friendly

Verdicts: SAFE_TO_INSTALL · REVIEW_BEFORE_INSTALL · DO_NOT_INSTALL — every finding carries file:line and plain-English evidence. A verdict is a gate for humans, never a black box.


The flow

  1. Vet any target: npm / PyPI / GitHub / local directory.
  2. Read the verdict + findings (evidence, not vibes).
  3. Configure: pick your harness, paste the emitted config block.
  4. Gate it in CI with --gate (exit 1 on DO_NOT_INSTALL).

Three surfaces, one engine

Surface Use
Library from mcp_vet import vet, PolicyVetResult (verdict, findings, provenance)
CLI mcp-vet <target> [--json] [--gate] [--strict] [--harness ...]
MCP server mcp-vet-server — tools: vet_server, vet_directory, get_verdict, list_scanners, list_harnesses, get_config

Targets

npm:pkg            npm registry + tarball        (bare names default to npm)
pypi:pkg           PyPI JSON + sdist/wheel
gh:owner/repo      GitHub metadata + source
./path             local source directory (offline)

Harness adapters (any harness, paste-ready)

--harness emits the exact config block for your tool:

harness output
generic universal mcpServers block
claude-code claude mcp add <name> -- <cmd> <args>
cursor .cursor/mcp.json
vscode .vscode/mcp.json (VS Code servers schema)
hermes ~/.hermes/config.yaml mcp_servers block

--harness all prints every adapter. Programmatic: config_for(harness, ServerSpec(...)).

Policy (calibrated defaults, --strict to disable)

Static analysis must not cry wolf. Defaults, learned by vetting the real ecosystem:

  • Examples/tests/docs are informationalexamples/, tests/, docs/ code can't block a package on its own (strict restores raw findings).
  • Fake secrets don't countsk-test-…, example, xxxx literals are placeholders, not exfiltration.
  • Trusted-host auth is normal — credentials sent to a host named in the file (constant or literal) is client auth; HIGH only when the destination host appears nowhere in the code.
  • Host interpolation → REVIEWhttps://${host}/… is a strong signal, but static analysis can't prove the host is user-controlled; a human decides. Strict mode blocks on it.

JSON schema (stable)

{
  "target": "npm:some-server", "kind": "npm", "version": "1.2.3",
  "verdict": {
    "level": "REVIEW_BEFORE_INSTALL",
    "summary": "3 finding(s); 0 high, 1 medium.",
    "findings": [
      {"scanner": "ssrf", "severity": "medium", "message": "...",
       "file": "dist/index.js", "line": 41, "evidence": "fetch(url)"}
    ]
  },
  "provenance": {"version": "1.2.3", "license": "MIT",
                 "source_url": "git+https://...", "source": "npm"},
  "files_scanned": 214, "duration_s": 1.7
}

Scanners

ssrf · exec · secrets · auth · provenance · deps — static, local-first (no telemetry, no cloud round-trips; the cache is a local SQLite file under ~/.cache/mcp-vet).

Verification

python3 -m unittest discover -s tests    # 48 checks: golden corpus is the quality bar

The golden corpus is the contract: known-good fixtures must never carry HIGH findings; malicious fixtures must always block. The ecosystem scan (scripts/ecosystem_scan.py) keeps the tool honest against real packages.

Honest limits

Static analysis has false positives and negatives. A verdict is a gate for humans, not a replacement for them — read the evidence. Sandboxed execution, egress audit-trail, and live CVE lookups are planned for v2.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mcp_vetting-0.2.0.tar.gz (24.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mcp_vetting-0.2.0-py3-none-any.whl (26.6 kB view details)

Uploaded Python 3

File details

Details for the file mcp_vetting-0.2.0.tar.gz.

File metadata

  • Download URL: mcp_vetting-0.2.0.tar.gz
  • Upload date:
  • Size: 24.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.11.15

File hashes

Hashes for mcp_vetting-0.2.0.tar.gz
Algorithm Hash digest
SHA256 4ef0c6eee36f2950f4c6af2ef884fe690f87936ea3f6dd95a4f9e3b41c106e18
MD5 49fd370b2edc3627c1edc5199c89cf27
BLAKE2b-256 d9b4a2c562fa71a0e32e6db6e9b9104a4f148dddc05c0d80991b6b38e69036b9

See more details on using hashes here.

File details

Details for the file mcp_vetting-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: mcp_vetting-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 26.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.11.15

File hashes

Hashes for mcp_vetting-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 483b225b3ebe69d704bc2bfa41830f7fb8a2bfb6ffe714b80a2a7e04fadd389e
MD5 28b8a304a0ea3cfc5c64c0ae6540ea68
BLAKE2b-256 c8cc6ba1e235dd4eeb4236812b6103e069d97d0401ef08a34b99fb9f5c29ef62

See more details on using hashes here.

Release history Release notifications | RSS feed

0.2.2

2 files

0.2.1

2 files

This release

0.2.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page