Last updated: July 21, 2026
MCP Trust Checker (“the Service”) is a free, non-commercial, open-source project. It is operated by its maintainers as a community resource (“we”, “us”, “the operator”) and is not a company, agency, certification body or commercial security vendor. By accessing mcptrustchecker.com, the MCP Trust Registry, the public API, the CLI, badges or any related material, you agree to these Terms of Use. If you do not agree, do not use the Service.
The Service runs a deterministic, automated, rule-based analysis of publicly available software package data (for example packages published on npm or PyPI) and publishes the results: a Trust Score, a letter grade, a capability profile, a coverage level and individual findings. The methodology and rules are openly documented. The analysis is fully automated — no human reviews, audits or investigates any package before its result is published.
This section is the basis on which every result of the Service is offered, and you accept it by using the Service:
Results are provided for general information only. They are not security advice, engineering advice, legal advice, compliance advice or any other form of professional advice, and they are not a substitute for your own review, testing and judgment. You must independently evaluate any software before installing or relying on it, especially in production, safety-relevant or security-sensitive environments. Any decision you make on the basis of a Result — including installing, not installing, recommending, publishing or removing software — is your decision alone and at your sole risk.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE AND ALL RESULTS ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF ACCURACY, COMPLETENESS, TIMELINESS, RELIABILITY, AVAILABILITY, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE OR NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE OR SECURE, THAT RESULTS WILL BE CORRECT OR CURRENT, OR THAT DEFECTS WILL BE CORRECTED.
THE SERVICE IS PROVIDED FREE OF CHARGE, AS A VOLUNTEER-RUN COMMUNITY PROJECT. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW: (a) WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, BUSINESS, GOODWILL, REPUTATION, DATA OR ANTICIPATED SAVINGS, ARISING OUT OF OR IN CONNECTION WITH THE SERVICE OR ANY RESULT, WHETHER BASED ON CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY OR ANY OTHER THEORY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES; AND (b) OUR TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS RELATING TO THE SERVICE SHALL NOT EXCEED THE AMOUNT YOU PAID US FOR THE SERVICE (WHICH IS ZERO) OR, WHERE A CAP OF ZERO IS NOT PERMITTED, THE SMALLEST AMOUNT PERMITTED BY APPLICABLE LAW. NOTHING IN THESE TERMS EXCLUDES OR LIMITS LIABILITY THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE MANDATORY LAW.
You use the Service at your own risk and are solely responsible for anything you do with Results, including republishing them or making decisions based on them. If you republish or quote a Result you must present it accurately, dated, and as the automated opinion that it is. To the extent permitted by applicable law, you agree to indemnify and hold harmless the operator, maintainers and contributors of the Service from claims, damages and reasonable costs arising out of your use of the Service, your violation of these Terms, or your misrepresentation of any Result.
If you are the author, maintainer or rights holder of a listed package and believe a Result is based on incorrect data, or you want your package re-scanned or removed from the Registry, email [email protected]. We review such requests in good faith and will normally re-scan on request; where the underlying data was demonstrably wrong we will correct or remove the affected Result. Whether and how to publish, correct or remove any content remains at our sole editorial discretion. This process is the exclusive route for challenging a Result, and your sole and exclusive remedy for any disagreement with the Service or its Results is to stop using the Service and, if applicable, to request delisting.
You must not: (a) use the Service in violation of applicable law; (b) misrepresent Results, present a Result as a human-performed audit or a certification, or use Results to harass, defame or deceive; (c) attempt to disrupt, overload, probe or gain unauthorised access to the Service; (d) circumvent rate limits, resell or white-label the Service or the API without permission; (e) scrape the Registry at volumes that degrade the Service where the API or open-source scanner would serve the same purpose; or (f) use the name of the Service to imply endorsement of any product.
The public API is free and provided for reasonable, fair use. API keys are personal, may be rate-limited, and may be suspended or revoked at any time, particularly for abuse. We may change, limit or discontinue the API (or any part of the Service) at any time without notice or liability. Automated decisions in your own systems that consume API responses are your responsibility (see Sections 2–6).
You may embed an unmodified score badge for a listed package provided it links back to that package's Registry page and is not presented as a certification or guarantee. Badges update automatically and reflect the latest scan, which may change. We may revoke embedding permission in cases of misuse.
The open-source scanner is licensed separately under its own licence (MIT) in its repository; nothing in these Terms restricts your rights under that licence. The content of this website (text, design, the Registry presentation) belongs to the project and may not be copied wholesale or used to create a misleadingly similar service. Feedback you send us may be used to improve the Service without obligation to you.
We may modify these Terms, the methodology, the algorithm, the Registry and any part of the Service at any time. The current version of these Terms is always available at this page, with its “Last updated” date. Your continued use after a change constitutes acceptance. We may suspend or terminate access (including API keys) at any time, particularly to protect the Service or comply with law.
These Terms apply to the fullest extent permitted by the law that applies to you; any mandatory consumer rights you have under that law remain unaffected. If any provision of these Terms is held unenforceable, the remaining provisions remain in force, and the unenforceable provision is replaced by an enforceable one that comes closest to its intent. Our failure to enforce a provision is not a waiver. These Terms are the entire agreement between you and us regarding the Service and supersede any prior understandings.
Questions about these Terms: [email protected]. See also the Privacy Policy.