MCP Trust Checker is a free, non-commercial open-source project, so there is exactly one channel and no ticket system to navigate: [email protected]. Everything below lands in that same inbox — the headings are only there to help you say what you need in the first line.
If you maintain a listed package, this is the fastest thing to write about. Send the package name and what you believe is incorrect. Results are recomputed on request, and where the underlying data was demonstrably wrong we correct or remove the entry. Delisting requests from a package's own maintainer are honoured. The full process is in the Terms of Use.
Worth knowing before you write: a low grade is not an accusation. Every score is produced by a
published deterministic algorithm reading the package's own code — you can reproduce
any result yourself with npx mcptrustchecker, and the individual findings with their evidence are on
the server's page.
The free API issues keys through its own form — use it first. Write here if a key request needs a nudge, if you are planning unusual volume, or if something in the API behaves differently from the documentation.
Found a vulnerability in this site, the API, or the scanner itself? Please report it privately to [email protected] before disclosing it publicly, and allow reasonable time for a fix. Include steps to reproduce. Reports are welcome and credited if you want them to be.
The engine is open source. Detection bugs, rule proposals and false-positive reports are best filed as issues on GitHub, where the discussion stays public and reviewable alongside the code — that is the whole point of an auditable methodology. Email works too if you would rather not open an issue.
Send the npm or PyPI package name. The only requirement is that it is a published package — listing is free and automated, and no placement or ranking can be bought. You can also check any package yourself right now with the free scan API, without asking anyone.
This is a volunteer-run project, not a company with a support desk — replies are best-effort, usually within a few days. Correction, rescan and security reports are always prioritised over everything else. There is no phone line and no postal address: the project has no legal entity behind it.
Write to [email protected] — see also the Terms of Use and the Privacy Policy.