{"_id":"@agentopssec/mcp-radar","name":"@agentopssec/mcp-radar","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@agentopssec/mcp-radar","version":"1.0.0","description":"Trust scores for MCP servers.","type":"module","homepage":"https://AgentOpsSec.com/projects/mcp-radar","repository":{"type":"git","url":"git+https://github.com/AgentOpsSec/mcp-radar.git"},"bugs":{"url":"https://github.com/AgentOpsSec/mcp-radar/issues"},"bin":{"mcp-radar":"bin/mcp-radar.js"},"scripts":{"test":"node --test","check":"node --check bin/mcp-radar.js && node --test"},"keywords":["mcp","registry","trust","security","score"],"license":"MIT","engines":{"node":">=20"},"publishConfig":{"access":"public"},"author":{"name":"Aunt Gladys Nephew","url":"https://auntgladysnephew.com"},"gitHead":"6d8b196d9333f3193bd814ef7250f931a03978ca","_id":"@agentopssec/mcp-radar@1.0.0","_nodeVersion":"25.6.1","_npmVersion":"11.9.0","dist":{"integrity":"sha512-3PeQuAKkTpnnYKxzRldDLdisB012qw9PKRnJckzxb5U1hjb0jY8zVKmtlyQqBNKXzZdNowUq1hyHInBjitBT8g==","shasum":"0de9b96c537d1cbbf5a4c62ed8c16b31a87d4def","tarball":"https://registry.npmjs.org/@agentopssec/mcp-radar/-/mcp-radar-1.0.0.tgz","fileCount":13,"unpackedSize":38659,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIC6MypPqZVbdsfLmHMmTSzJlbPLQpGSfpt9mHOjOJYJ6AiBLhyz1ID30RTf5cTHzC4L8UmMRC8HSxk4CG+LErX4J8Q=="}]},"_npmUser":{"name":"agentopssec","email":"agentopssecurity@gmail.com"},"directories":{},"maintainers":[{"name":"agentopssec","email":"agentopssecurity@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-radar_1.0.0_1777236593773_0.7813870788690114"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-26T20:49:53.675Z","1.0.0":"2026-04-26T20:49:53.918Z","modified":"2026-04-26T20:49:54.138Z"},"maintainers":[{"name":"agentopssec","email":"agentopssecurity@gmail.com"}],"description":"Trust scores for MCP servers.","homepage":"https://AgentOpsSec.com/projects/mcp-radar","keywords":["mcp","registry","trust","security","score"],"repository":{"type":"git","url":"git+https://github.com/AgentOpsSec/mcp-radar.git"},"author":{"name":"Aunt Gladys Nephew","url":"https://auntgladysnephew.com"},"bugs":{"url":"https://github.com/AgentOpsSec/mcp-radar/issues"},"license":"MIT","readme":"# MCP Radar\n\n**Trust scores for MCP servers.**\n\nMCP Radar is a public trust and discovery layer for MCP servers. It helps\ndevelopers evaluate MCP servers based on permissions, maintenance, install\nmethod, package quality, documentation, and security risk before installing\nthem.\n\nThink of it as:\n\n```txt\nThe trust index for MCP servers\n```\n\n## Why This Exists\n\nMCP servers are becoming a new supply chain for AI agents. Developers need to\nknow whether a server is maintained, documented, permissioned reasonably, and\nsafe enough to connect to a real agent workflow.\n\nMCP Radar answers questions like:\n\n- Who maintains this MCP server?\n- What permissions does it require?\n- Does it expose filesystem, shell, network, or database access?\n- Is the package pinned and released responsibly?\n- Is the repository active?\n- Does the project have clear docs and schemas?\n- Are there known vulnerabilities?\n- Is the install method safe?\n- How does it compare to alternatives?\n\nMCP Radar turns those signals into transparent trust scores.\n\n## Install\n\n```bash\nnpm install -g @agentopssec/mcp-radar\n```\n\nOr run it without installing:\n\n```bash\nnpx -y @agentopssec/mcp-radar search github\n```\n\n## Update\n\n```bash\nmcp-radar update          # check the registry, prompt before installing\nmcp-radar update --yes    # update without prompting\n```\n\n## Primary Workflow\n\nMCP Radar starts with searchable server profiles and CLI score lookup:\n\n```bash\nmcp-radar score owner/repo\n```\n\nThe workflow should do three things well:\n\n1. Show whether an MCP server is safe enough to install.\n2. Explain the signals behind the score.\n3. Make scores reusable through profiles, badges, and JSON.\n\n## CLI\n\n```bash\nmcp-radar search github\nmcp-radar score owner/repo\nmcp-radar compare github-server filesystem-server\nmcp-radar badge owner/repo\nmcp-radar submit ./mcp-server.json\nmcp-radar score-doctor ./mcp-doctor-scan.json\nmcp-radar validate\nmcp-radar registry update --from registry.json\nmcp-radar update [--yes]\n```\n\n## Standalone and Stack Use\n\nMCP Radar runs on its own using its curated local registry. Projects can also\nprovide `.mcp-radar/registry.json` for local/private server profiles:\n\n```bash\nmcp-radar search github\nmcp-radar score modelcontextprotocol/server-github\nmcp-radar registry update --from ./registry.json\n```\n\nWhen used with the full AgentOpsSec stack, it can score servers found by MCP\nDoctor without importing MCP Doctor code:\n\n```bash\nmcp-doctor scan --json --output mcp-doctor-scan.json\nmcp-radar score-doctor ./mcp-doctor-scan.json\n```\n\n## What MCP Radar Scores\n\nMCP Radar scores MCP servers using signals such as:\n\n- Repository activity\n- Maintainer activity\n- Stars and forks\n- License\n- Package age\n- Release history\n- Known vulnerabilities\n- Install method\n- Required permissions\n- Tool categories\n- Filesystem access\n- Shell access\n- Network access\n- Token handling\n- Environment variables\n- Docker support\n- Documentation quality\n- Schema quality\n- Prompt injection risk indicators\n\n## Example Profile\n\n```txt\nMCP Radar Score by github.com/AgentOpsSec\n\nOfficial GitHub MCP Server\nScore: A-\nRisk: Medium\nReason: Powerful repo access, but maintained and documented\n\nRandom Database MCP Server\nScore: D\nRisk: High\nReason: Broad database access, low maintainer activity, no version pinning, weak docs\n```\n\n## Score Shape\n\n```json\n{\n  \"tool\": {\n    \"name\": \"MCP Radar\",\n    \"by\": \"github.com/AgentOpsSec\",\n    \"repository\": \"github.com/AgentOpsSec/mcp-radar\"\n  },\n  \"name\": \"example-mcp-server\",\n  \"score\": \"B-\",\n  \"risk\": \"medium\",\n  \"categories\": [\"github\", \"filesystem\"],\n  \"findings\": [\n    {\n      \"type\": \"permission\",\n      \"severity\": \"medium\",\n      \"message\": \"Requires repository write access\"\n    },\n    {\n      \"type\": \"maintenance\",\n      \"severity\": \"low\",\n      \"message\": \"Last release was 22 days ago\"\n    }\n  ]\n}\n```\n\n## Public Outputs\n\nMCP Radar is designed to produce reusable public artifacts:\n\n- MCP server profile pages\n- Searchable registry entries\n- Transparent scoring breakdowns\n- JSON API responses\n- Score badges\n- Community submissions\n- Comparison views\n\n## Design Principles\n\n- Open scoring model\n- Transparent findings\n- Public by default\n- Useful before installation\n- Community-extensible registry\n- Clear permission labels\n- Security and maintenance signals together\n- Easy integration with local scanners\n\n## Initial Release Scope\n\nThe initial release includes a public registry, curated MCP server profiles,\ntransparent scoring, search, badges, JSON output, and community submissions.\n\n### 1.0: Curated Registry\n\n- Build a public MCP server registry\n- Add an initial curated server list\n- Create server profile pages\n- Label tool categories and permissions\n- Show install method and package metadata\n- Include repository and license metadata\n\n### 1.0: Scoring Model\n\n- Define a transparent score model\n- Score maintenance signals\n- Score permission risk\n- Score install safety\n- Score documentation and schema quality\n- Explain each finding behind the final score\n\n### 1.0: Search, API, and Badges\n\n- Add basic server search\n- Add server comparison\n- Generate score badges\n- Expose public JSON score output\n- Support community submissions\n- Make scores consumable by local tools\n\n### Registry Validation\n\n```bash\nmcp-radar validate\nmcp-radar validate ./registry.json\nmcp-radar registry update --from ./registry.json\n```\n\nRegistry updates are local to the current project and write\n`.mcp-radar/registry.json`.\n\n\n## Output\n\nReports use plain-language status words rather than raw exit codes:\n\n- `ok` — the step ran successfully (green).\n- `failed (exit N)` — the step exited non-zero (red); the original code is preserved.\n- `skipped (reason)` — the step was not applicable (dim).\n\nSeverity colors follow the AgentOpsSec palette (safe = green, warning = amber, risk = red). The palette honors `NO_COLOR` and `FORCE_COLOR`, and JSON / CSV output stays plain.\n\n\n- Repo: https://github.com/AgentOpsSec/mcp-radar\n- npm: https://www.npmjs.com/package/@agentopssec/mcp-radar\n- AgentOpsSec stack: https://github.com/AgentOpsSec/stack\n- Website: https://AgentOpsSec.com\n\n## Author\n\nCreated and developed by **Aunt Gladys Nephew**.\n\n- Website: https://auntgladysnephew.com\n- GitHub: https://github.com/auntgladysnephew\n- X: https://x.com/AGNonX\n","readmeFilename":"README.md","_rev":"1-18b2e62edbaa3448a07036bc083cdd62"}