mcptrustchecker_
How it scans Trust Score Scoring FAQ MCP Trust Registry Blog
API Star
How it scans Trust Score Scoring FAQ MCP Trust Registry Blog API
Home / Terms of Use

Terms of Use

Last updated: July 21, 2026

MCP Trust Checker (“the Service”) is a free, non-commercial, open-source project. It is operated by its maintainers as a community resource (“we”, “us”, “the operator”) and is not a company, agency, certification body or commercial security vendor. By accessing mcptrustchecker.com, the MCP Trust Registry, the public API, the CLI, badges or any related material, you agree to these Terms of Use. If you do not agree, do not use the Service.

1. What the Service is

The Service runs a deterministic, automated, rule-based analysis of publicly available software package data (for example packages published on npm or PyPI) and publishes the results: a Trust Score, a letter grade, a capability profile, a coverage level and individual findings. The methodology and rules are openly documented. The analysis is fully automated — no human reviews, audits or investigates any package before its result is published.

2. Scores and findings are automated opinions, not facts

This section is the basis on which every result of the Service is offered, and you accept it by using the Service:

  • Every Trust Score, grade, finding, capability level, coverage level, ranking, badge and any other output of the Service (“Results”) is a statement of opinion, produced automatically by applying a disclosed, deterministic algorithm to publicly available data at a particular moment in time. Results are not statements of verified fact.
  • A low score, a failing grade or a finding is not an allegation that a package, its author, maintainer or publisher is malicious, negligent, dishonest, infringing or engaged in any wrongdoing. It reflects only that the algorithm's published rules matched certain observable properties of the published artifact.
  • A high score is not a certification, guarantee, endorsement or assurance that a package is safe, secure, functional, legal or fit for any purpose. Automated analysis has inherent limits and cannot detect every risk, and the Service states openly what a scan could not see.
  • Results can be outdated, incomplete or wrong — for example because the package changed after the scan, the public registry served incomplete data, or the algorithm's rules produced a false positive or a false negative. You accept this possibility as an unavoidable property of automated analysis.
  • You may disagree with the methodology, the rules, the weighting or any Result. Disagreement with an opinion or with an algorithm's design is not a defect of the Service and gives rise to no claim. The methodology is public precisely so that anyone can evaluate, reproduce or criticise it, or run the open-source scanner themselves.

3. No professional advice

Results are provided for general information only. They are not security advice, engineering advice, legal advice, compliance advice or any other form of professional advice, and they are not a substitute for your own review, testing and judgment. You must independently evaluate any software before installing or relying on it, especially in production, safety-relevant or security-sensitive environments. Any decision you make on the basis of a Result — including installing, not installing, recommending, publishing or removing software — is your decision alone and at your sole risk.

4. No warranties

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE AND ALL RESULTS ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF ACCURACY, COMPLETENESS, TIMELINESS, RELIABILITY, AVAILABILITY, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE OR NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE OR SECURE, THAT RESULTS WILL BE CORRECT OR CURRENT, OR THAT DEFECTS WILL BE CORRECTED.

5. Limitation of liability

THE SERVICE IS PROVIDED FREE OF CHARGE, AS A VOLUNTEER-RUN COMMUNITY PROJECT. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW: (a) WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, BUSINESS, GOODWILL, REPUTATION, DATA OR ANTICIPATED SAVINGS, ARISING OUT OF OR IN CONNECTION WITH THE SERVICE OR ANY RESULT, WHETHER BASED ON CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY OR ANY OTHER THEORY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES; AND (b) OUR TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS RELATING TO THE SERVICE SHALL NOT EXCEED THE AMOUNT YOU PAID US FOR THE SERVICE (WHICH IS ZERO) OR, WHERE A CAP OF ZERO IS NOT PERMITTED, THE SMALLEST AMOUNT PERMITTED BY APPLICABLE LAW. NOTHING IN THESE TERMS EXCLUDES OR LIMITS LIABILITY THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE MANDATORY LAW.

6. Your responsibility and indemnity

You use the Service at your own risk and are solely responsible for anything you do with Results, including republishing them or making decisions based on them. If you republish or quote a Result you must present it accurately, dated, and as the automated opinion that it is. To the extent permitted by applicable law, you agree to indemnify and hold harmless the operator, maintainers and contributors of the Service from claims, damages and reasonable costs arising out of your use of the Service, your violation of these Terms, or your misrepresentation of any Result.

7. Third-party software, data and trademarks

  • All analysed packages are third-party software. Package names, logos and trademarks belong to their respective owners. Their appearance in the Registry or in Results does not imply any affiliation with, sponsorship of, or endorsement by or of the Service.
  • The Service processes metadata and published artifacts obtained from public registries (such as npm and PyPI) and other public sources as-is. We are not responsible for the accuracy of that third-party data.
  • Listing in the MCP Trust Registry is automated and free; no one can pay for a listing, a score or a ranking, and no listed project has any commercial relationship with the Service unless explicitly stated.

8. Corrections, re-scans and removal

If you are the author, maintainer or rights holder of a listed package and believe a Result is based on incorrect data, or you want your package re-scanned or removed from the Registry, email [email protected]. We review such requests in good faith and will normally re-scan on request; where the underlying data was demonstrably wrong we will correct or remove the affected Result. Whether and how to publish, correct or remove any content remains at our sole editorial discretion. This process is the exclusive route for challenging a Result, and your sole and exclusive remedy for any disagreement with the Service or its Results is to stop using the Service and, if applicable, to request delisting.

9. Acceptable use

You must not: (a) use the Service in violation of applicable law; (b) misrepresent Results, present a Result as a human-performed audit or a certification, or use Results to harass, defame or deceive; (c) attempt to disrupt, overload, probe or gain unauthorised access to the Service; (d) circumvent rate limits, resell or white-label the Service or the API without permission; (e) scrape the Registry at volumes that degrade the Service where the API or open-source scanner would serve the same purpose; or (f) use the name of the Service to imply endorsement of any product.

10. API terms

The public API is free and provided for reasonable, fair use. API keys are personal, may be rate-limited, and may be suspended or revoked at any time, particularly for abuse. We may change, limit or discontinue the API (or any part of the Service) at any time without notice or liability. Automated decisions in your own systems that consume API responses are your responsibility (see Sections 2–6).

11. Badges and embedding

You may embed an unmodified score badge for a listed package provided it links back to that package's Registry page and is not presented as a certification or guarantee. Badges update automatically and reflect the latest scan, which may change. We may revoke embedding permission in cases of misuse.

12. Intellectual property

The open-source scanner is licensed separately under its own licence (MIT) in its repository; nothing in these Terms restricts your rights under that licence. The content of this website (text, design, the Registry presentation) belongs to the project and may not be copied wholesale or used to create a misleadingly similar service. Feedback you send us may be used to improve the Service without obligation to you.

13. Changes and termination

We may modify these Terms, the methodology, the algorithm, the Registry and any part of the Service at any time. The current version of these Terms is always available at this page, with its “Last updated” date. Your continued use after a change constitutes acceptance. We may suspend or terminate access (including API keys) at any time, particularly to protect the Service or comply with law.

14. General

These Terms apply to the fullest extent permitted by the law that applies to you; any mandatory consumer rights you have under that law remain unaffected. If any provision of these Terms is held unenforceable, the remaining provisions remain in force, and the unenforceable provision is replaced by an enforceable one that comes closest to its intent. Our failure to enforce a provision is not a waiver. These Terms are the entire agreement between you and us regarding the Service and supersede any prior understandings.

15. Contact

Questions about these Terms: [email protected]. See also the Privacy Policy.

mcptrustchecker
GitHub npm Methodology Rules MIT License Contact Terms of Use Privacy
Free open-source MCP security scanner for Model Context Protocol servers · offline & deterministic
© 2026 MCP Trust Checker contributors · [email protected]