mcp-mcp
npm
v0.0.0
Published by an unidentified publisher — no publish provenance and no vendor-owned scope, so the publisher could not be verified. The repository link below is self-declared.
Every server starts at 100. These are the exact deductions the deterministic engine applied — each one reproducible, none of it an opinion or an LLM's guess:
| Points | What was found | Category |
|---|---|---|
| −6.7 | Possible combosquat of mcp ×4 MTC-SUP-006 | supply-chain |
| −2.1 | Package has no source repository MTC-SUP-011 | supply-chain |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind the deduction.
"mcp-mcp" is "mcp" with a decorative suffix — a common combosquat pattern.
Fix: Confirm you meant "mcp". Install packages only from their documented, official name.
Location: package mcp-mcp
"mcp-mcp" is "@playwright/mcp" with a decorative suffix — a common combosquat pattern.
Fix: Confirm you meant "@playwright/mcp". Install packages only from their documented, official name.
Location: package mcp-mcp
"mcp-mcp" is "@stripe/mcp" with a decorative suffix — a common combosquat pattern.
Fix: Confirm you meant "@stripe/mcp". Install packages only from their documented, official name.
Location: package mcp-mcp
"mcp-mcp" is "@browsermcp/mcp" with a decorative suffix — a common combosquat pattern.
Fix: Confirm you meant "@browsermcp/mcp". Install packages only from their documented, official name.
Location: package mcp-mcp
"mcp-mcp" declares no repository URL, so its published artifact cannot be compared against reviewable source.
Fix: Prefer packages that link to public, reviewable source.
Location: package mcp-mcp
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.0.0 latest |
A 91/100 | 5 | 1.5.0 | 2026-07-22 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan mcp-mcp --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 2 side by side →
Security scan results for the 199bio Mcp Limitless MCP server.
Security scan results for the 1mcp MCP server.
Security scan results for the 1stay MCP server.
Generates production-ready UI components from natural language, inspired by v0.
Security scan results for the 2slides MCP server.
Security scan results for the 3d MCP server.