https://app.duvera.ai/mcp
Remote
v1.0
Published by app.duvera.ai — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
Governed AI actions with signed, verifiable receipts: free keyless reads, human-approved writes.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 6 = 94. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
This server (without client built-ins) exposes a complete data-exfiltration chain: bluesky__trending_get ⇒ datadog__logs_view → venmo__payment_request. Untrusted input is ingested, private data is read, and it can be sent to an external sink — and at least one leg is a direct schema wire (⇒), where a producer's output drops straight into a free-text parameter of the next tool, so the chain needs little agent cooperation. Static analysis proves the primitive exists, not that a specific run will occur.
Fix: Remove one leg of the trifecta: isolate untrusted-input tools from secret-reading tools and from egress tools, or require human approval between them.
Location: flow bluesky__trending_get → datadog__logs_view → venmo__payment_request
Tool "duvera__github_read_file" takes a path parameter "path" with no constraint. Without a canonicalize-and-contain check (not visible statically), this permits ../ traversal outside the intended root.
Fix: Resolve and verify the path stays within an allowed root; reject traversal sequences.
Location: tool duvera__github_read_file · inputSchema.properties.path
Each tool and what it can reach — enumerated from the running server.
bluesky__trending_getingests untrusted inputdatadog__logs_viewreads sensitive dataduvera__github_read_filereads sensitive datahackernews__stories_topingests untrusted inputpostgres__sql_readreads sensitive datavenmo__payment_requestnetwork egressamazon__package_trackno sensitive capabilityapplehealth__heart_rate_readno sensitive capabilityapplehealth__sleep_readno sensitive capabilityapplehealth__steps_readno sensitive capabilitychase__balance_checkno sensitive capabilitydelta__boardingpass_showno sensitive capabilityduvera__dev_npm_packageno sensitive capabilityduvera__dev_pypi_packageno sensitive capabilityduvera__dev_stackoverflow_searchno sensitive capabilityduvera__finance_crypto_priceno sensitive capabilityduvera__finance_exchange_ratesno sensitive capabilityduvera__food_recipe_searchno sensitive capabilityduvera__food_restaurant_searchno sensitive capabilityduvera__geo_geocodeno sensitive capabilityduvera__github_latest_releaseno sensitive capabilityduvera__github_search_reposno sensitive capabilityduvera__news_searchno sensitive capabilityduvera__news_top_storiesno sensitive capabilityduvera__reference_dictionaryno sensitive capabilityduvera__reference_public_holidaysno sensitive capabilityduvera__time_nowno sensitive capabilityduvera__travel_flight_searchno sensitive capabilityduvera__weather_air_qualityno sensitive capabilityduvera__weather_currentno sensitive capabilityduvera__wiki_searchno sensitive capabilityduvera__wiki_summaryno sensitive capabilitygmail__mail_readno sensitive capabilitygoogle_workspace__mail_searchno sensitive capabilitygooglecalendar__availability_findno sensitive capabilitygrubhub__order_trackno sensitive capabilityinstacart__menu_searchno sensitive capabilitymaps__eta_shareno sensitive capabilitymicrosoft365__calendar_listno sensitive capabilitymicrosoft365__mail_searchno sensitive capabilitynotion__notes_searchno sensitive capabilityobsidian__notes_searchno sensitive capabilityopen_meteo__weather_forecastno sensitive capabilityopensky__flights_liveno sensitive capabilityshazam__audio_identifyno sensitive capabilityslack__message_searchno sensitive capabilitysouthwest__flight_statusno sensitive capabilitytelegram__message_readno sensitive capabilitytwitter__tweets_searchno sensitive capabilityuber__fare_estimateno sensitive capabilityunited__flight_statusno sensitive capabilitywallet__boardingpass_showno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0 latest |
A 94/100 | 2 | 1.13.0 | 2026-09-06 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan https://app.duvera.ai/mcp --online
A Model Context Protocol server implementation for AdGuard Home that enables AI agents to query and manage DNS records, filtering rules and more
Identity oracle and trust layer for autonomous AI agents. Bidirectional KYA and trust scoring.
MCP server with Airtable integration
A free one-minute reset for people, delivered by AI, with no account or personal data.
Access SEC filings efficiently, save time and tokens, and get cited answers.
A smart [MCP](https://modelcontextprotocol.io) server for [AniList](https://anilist.co) that gets your anime/manga taste - not just API calls.