Model Context Protocol / MCP

Model Context Protocol Servers

Protocols & Tool Integration TypeScript Grade B Listed NOASSERTION
Listing state
Listed
HVTrust
65.0/100 · Grade B
Last push
2026-06-04 · 0d ago
Recent change
Rank +6

Quick Trust Read

Verdict
Promising trust profile, but some evidence still deserves review.
65.0/100 · Grade B
Strongest Signal
Maintenance
16.6/20
Weakest Signal
Safety / Integrity
11.8/25
What Would Improve It
Publish package provenance or release attestations for stronger supply-chain evidence.
Recent Changes
2026-06-01
Rank Moved
Rank dropped 15 spots (#65 → #80)
2026-05-29
HVTrust Changed
HVTrust up 9.9pts (54.5 → 64.4)
2026-05-28
Rank Moved
Rank dropped 53 spots (#23 → #76)
Maintainer Checklist
Raise Scorecard signals Current OSSF Scorecard is 6.4/10. Tighten the weakest checks to improve public safety evidence.
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
87.7
Activity Score · out of 100
65.0
HVTrust Score · out of 100
#96
Global Rank · of 203
#3

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade B reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Full methodology →

Signals refreshed 2026-06-04 20:15 UTC · Repo last pushed today

Rank Trend

2026-05-25 2026-06-04

Activity & Reach

Stars
86.7k
Forks
10.9k
Last Push
2026-06-04
today
Commits (4 wk)
13
Downloads (7d)
HN mentions (30d)
7
Open Issues
491
Rank Change
▼8
was #88

Analysis

HVTrust Dimensions

65.0 / 100 · 100.0% confidence
Safety / IntegrityOSSF, provenance, signatures
11.8 / 25
Identity / ProvenanceListing and build link
10.8 / 18
TransparencyLicense and public checks
13.9 / 17
MaintenanceFreshness and commits
16.6 / 20
AdoptionStars and downloads
11.9 / 20

Activity Inputs

87.7 / 100
StarsRepository reach
29.6 / 30
FreshnessLast push recency
25.0 / 25
ActivityRecent commits
14.3 / 25
CommunityFork signal
18.8 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
6.4 / 10
via deps.dev · OpenSSF
Signed Commits
75%
of last 100 commits verified
Binary-Artifacts 10
Branch-Protection 6
CI-Tests 9
CII-Best-Practices 0
Code-Review 10
Contributors 10
Dangerous-Workflow 10
Dependency-Update-Tool 10
Fuzzing 0
License 9
Maintained 10
Packaging 10
Pinned-Dependencies 2
SAST 0
Security-Policy 10
Signed-Releases -1
Token-Permissions 0
Vulnerabilities 0

Is Model Context Protocol / MCP safe?

Model Context Protocol / MCP has a mixed signal profile. Some trust indicators are present, others are missing. Whether it is safe for your use case depends on which gaps matter to you — review the breakdown below before adopting in production.
Does Model Context Protocol / MCP publish package provenance?
No published build provenance is currently detected for Model Context Protocol / MCP. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does Model Context Protocol / MCP have an OpenSSF Scorecard?
Model Context Protocol / MCP has an OpenSSF Scorecard score of 6.4/10. The Scorecard checks for branch protection, signed releases, dependency updates, fuzzing, code review, and other supply-chain hygiene items. See the full check breakdown on this page.
Is Model Context Protocol / MCP actively maintained?
Actively maintained. The repository was pushed to within the last 1 day(s).
What license does Model Context Protocol / MCP use?
Model Context Protocol / MCP ships under NOASSERTION. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are Model Context Protocol / MCP's commits signed?
75% of the last 100 commits to Model Context Protocol / MCP are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

Compare Model Context Protocol / MCP head-to-head

Runtime trust — coming soon

HVTrust currently scores supply-chain signals. We're adding runtime trust next: what an agent actually does when it runs — what it can reach, which tools it carries, what external services it depends on. Track progress on the roadmap →

  • MCP support
  • Tool / plugin surface
  • External service deps
  • Package provenance drift

Maintain Model Context Protocol / MCP?

HVTrust scores Model Context Protocol / MCP from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

HVTrust 2Rank 2Listed 1Scorecard 1Score 1
2026-06-01
Rank Moved
Rank dropped 15 spots (#65 → #80)
2026-05-29
HVTrust Changed
HVTrust up 9.9pts (54.5 → 64.4)
2026-05-28
Rank Moved
Rank dropped 53 spots (#23 → #76)
2026-05-28
Activity Score Changed
Activity score up 13pts (73 → 86)
2026-05-27
Scorecard Added
OSSF Scorecard: 6.4/10
2026-05-27
HVTrust Changed
HVTrust up 26.3pts (27.5 → 53.8)
2026-05-25
Newly Listed
First tracked at rank #26

Embed Badge Badge guide for maintainers →

HVTrust 65.0 Grade B
Markdown:
[![HVTrust](https://hvtracker.net/badge/model-context-protocol-mcp.svg)](https://hvtracker.net/agents/model-context-protocol-mcp)
HTML:
<a href="https://hvtracker.net/agents/model-context-protocol-mcp"><img src="https://hvtracker.net/badge/model-context-protocol-mcp.svg" alt="HVTrust"></a>

Other agents in Protocols & Tool Integration

Model Context Protocol / MCP head-to-head

Data sources
GitHub REST API (repo, commits, stars, forks, license) · OSSF Scorecard via deps.dev · Algolia HN Search API
Each agent's signals refresh once daily across 6 staggered batches. Methodology v3.1 · Raw JSON