{"site":{"name":"MCP Risk","tagline":"Approve MCPs once. Know when they change.","description":"Evidence-backed trust profiles for MCP repos and configs. Approve a known-good state and monitor what changes.","url":"https://risk.williamsmale.com"},"hero":{"headline":"Approval has a shelf life.","sub":"Servers get patched, descriptions get rewritten, and tools appear that nobody signed off on. We hold the surface you approved and measure everything after it against that.","capabilities":["Approval records","Config fingerprints","Drift evidence","Trust card gallery"]},"primer":{"title":"New to MCP?","paragraphs":["The Model Context Protocol (MCP) lets AI agents connect to external tools and data through MCP servers — local processes or remote services that expose actions like reading files, querying databases, or calling APIs.","That power is the risk. An MCP server can ship a tool whose description quietly instructs the agent to exfiltrate secrets, or change behavior after you approve it. MCP Risk reads the repo and config, produces a trust profile you can approve, and flags when the approved state drifts."]},"method":{"title":"A trust profile is not a scan. It is an approval record.","body":"The scanner only produces evidence. The product is the lifecycle around that evidence: who approved what, under which config, and what changed afterwards.","steps":[{"number":"01","title":"Evidence","body":"Extract declared tools, install commands, dependencies, env keys, permission surfaces, and risky code patterns."},{"number":"02","title":"Config","body":"Evaluate the actual launch context: command, args, tokens, filesystem scope, network exposure, and client."},{"number":"03","title":"Approval","body":"Bind decisions to repo version, config hash, policy version, analyzer version, reviewer, and environment."},{"number":"04","title":"Drift","body":"Trigger re-review when tools, descriptions, dependencies, env vars, or install commands change materially."}]},"reviewFlow":{"title":"Every MCP approval should leave evidence behind.","body":"A calm chain from tool request, to trust profile, to approval, to drift.","exampleSession":[{"kind":"cmd","text":"$ mcp-risk profile github.com/example/mcp-server"},{"kind":"out","text":"subject: github.com/example/mcp-server"},{"kind":"out","text":"config: 9f1c…42ab"},{"kind":"out","text":"verdict: approve_with_conditions"},{"kind":"cmd","text":"$ mcp-risk diff approved latest"},{"kind":"warn","text":"change: env_key_added GITHUB_TOKEN"},{"kind":"warn","text":"change: tool_added run_shell"},{"kind":"bad","text":"result: re-review required"}],"driftDiff":{"caption":"Approved profile vs. the live server, three weeks later.","verdict":"Approval lapsed — re-review required before this server runs again.","lines":[{"sign":" ","text":"subject: github.com/example/mcp-server"},{"sign":" ","text":"config: 9f1c…42ab"},{"sign":"+","text":"env_key_added: GITHUB_TOKEN"},{"sign":"+","text":"tool_added: run_shell"},{"sign":"-","text":"verdict: approve"},{"sign":"+","text":"verdict: re-review required"}]}},"callToAction":{"title":"Generate your first MCP trust profile.","body":"Submit a repo or config. See the verdict and summary instantly — add your email to unlock the full evidence and downloadable card."},"api":{"submit":{"method":"POST","path":"/api/submit","body":{"repoOrConfig":"<github url or mcp.json contents>"},"returns":"Queued or completed trust profile: profileUrl, publicSlug, status, verdict, riskLevel, and summary."},"profileStatus":{"method":"GET","path":"/api/profile/{publicSlug}/status","returns":"Current scan status and profile for a submitted subject."},"feed":{"method":"GET","path":"/api/feed","query":{"limit":"1-100, default 25","cursor":"opaque, from nextCursor"},"conditional":"Send If-None-Match; an unchanged poll returns 304 with no body.","returns":"Published advisories, newest first. Withdrawn advisories remain with withdrawn: true."},"feedAtom":{"method":"GET","path":"/api/feed.atom","returns":"The same advisories as Atom."},"advisory":{"method":"GET","path":"/api/advisory/{advisoryCode}","returns":"One advisory. Append .osv.json for an OSV-schema record."},"server":{"method":"GET","path":"/api/server/{publicSlug}","returns":"Reputation grade with its component arithmetic, plus the drift timeline."},"badge":{"method":"GET","path":"/api/server/{publicSlug}/badge.svg","returns":"Embeddable grade badge (SVG)."}},"crawler":{"policyUrl":"/crawler","userAgent":"mcp-risk-crawler-worker/1","snapshotUserAgent":"MCPRiskBot/1.0 (+https://mcprisk.dev/crawler)","contact":"crawler@mcprisk.dev","sources":[{"key":"official-registry","host":"registry.modelcontextprotocol.io","status":"manual-schedule-disabled","reads":"HTTPS GET of the public /v0.1/servers listing, including deleted records and cursor pages. Version claims come from listing records; detail URLs are not fetched.","cadence":"When an operator starts a Go v2 run; included in the default selection. An hourly schedule of at most 100 records per run is defined but disabled."},{"key":"github-registry","host":"api.mcp.github.com","status":"manual","reads":"HTTPS GET of the public /v0.1/servers listing, including deleted records and cursor pages. Version claims come from listing records; detail URLs are not fetched.","cadence":"Only when an operator starts a Go v2 run; included in the default selection."},{"key":"docker-catalog","host":"desktop.docker.com","status":"manual","reads":"HTTPS GET of /mcp/catalog/v3/catalog.json.","cadence":"Only when an operator starts a Go v2 run; included in the default selection."},{"key":"mcpservers-org","host":"mcpservers.org","status":"manual-opt-in","reads":"HTTPS GET of /sitemap.xml and its server-sitemap XML shards only. Listed server pages and /api/ are never fetched.","cadence":"Only when an operator explicitly selects this source and acknowledges its access and licensing constraints."}],"schedule":{"source":"official-registry","state":"disabled","interval":"hourly","maxRecordsPerRun":100,"maxRequestsPerRun":20,"maxDownloadMiBPerRun":32,"maxMinutesPerRun":3,"artifactRetentionDays":90,"readsRobotsTxt":false,"perHostRateLimit":false,"summary":"An hourly Official Registry schedule is defined but disabled; no crawler schedule is enabled. If enabled, each run reads at most 100 records from a stored cursor."},"rules":[{"heading":"Request bounds","items":["The default manual run selects the official registry, GitHub registry and Docker catalog, with at most 100 records per source. Operators can select fewer sources or change that bound.","A run is capped at 50,000 records, 500 HTTP requests, 250 MiB downloaded and 15 minutes. Each response also has an adapter-specific size cap.","Requests use HTTPS GET to explicitly allowed source origins. Redirects must stay on an allowed origin.","The Go v2 crawler does not fetch robots.txt or enforce a per-host request rate. That applies to manual runs and to the schedule below. Please email us to request exclusion."]},{"heading":"Scheduled Official Registry intake","items":["Disabled by default. It is not enabled, and no other source has a schedule.","If an operator enables it, it runs hourly against registry.modelcontextprotocol.io only and reads at most 100 records per run, continuing from a cursor stored in our database.","Each scheduled run is capped at 20 HTTP requests, 32 MiB downloaded and 3 minutes, on top of the per-response size cap.","Each run's artifact is stored privately and deleted after 90 days. Failed imports are retried a bounded number of times."]},{"heading":"Evidence handling","items":["The mcpservers.org sitemap contributes weak directory pointers only; it does not prove that a listed server belongs to any repository or package.","The crawler records source claims and attribution in a v2 artifact. Import and identity resolution happen separately; a source claim is not a verified security finding.","The intake crawler does not connect to listed MCP endpoints, execute tools or run code from a listed repository.","The separate snapshot worker may contact a declared MCP endpoint for initialize, notifications/initialized, tools/list, prompts/list and resources/list. It never invokes a listed tool. Its User-Agent is shown above."]}],"optOut":"Email crawler@mcprisk.dev with the source or host to exclude. We will stop selecting it for future manual and scheduled runs and confirm. The current Go v2 crawler does not read robots.txt, so a robots.txt rule alone does not change its behavior."},"machineSurfaces":["/llms.txt","/api/site","/ai","/crawler"]}