Servers get patched, descriptions get rewritten, and tools appear that nobody signed off on. We hold the surface you approved and measure everything after it against that.
The scanner only produces evidence. The product is the lifecycle around that evidence: who approved what, under which config, and what changed afterwards.
A calm chain from tool request, to trust profile, to approval, to drift.
subject: github.com/example/mcp-serverconfig: 9f1c…42abenv_key_added: GITHUB_TOKENtool_added: run_shellverdict: approveverdict: re-review requiredApproval lapsed — re-review required before this server runs again.
$ mcp-risk profile github.com/example/mcp-serversubject: github.com/example/mcp-serverconfig: 9f1c…42abverdict: approve_with_conditions$ mcp-risk diff approved latestchange: env_key_added GITHUB_TOKENchange: tool_added run_shellresult: re-review requiredThe Model Context Protocol (MCP) lets AI agents connect to external tools and data through MCP servers — local processes or remote services that expose actions like reading files, querying databases, or calling APIs.
That power is the risk. An MCP server can ship a tool whose description quietly instructs the agent to exfiltrate secrets, or change behavior after you approve it. MCP Risk reads the repo and config, produces a trust profile you can approve, and flags when the approved state drifts.
Submit a repo or config. See the verdict and summary instantly — add your email to unlock the full evidence and downloadable card.