MCP Trust Index
Every listing answers three questions: our assessment, the depth of our verification, and the identity behind the software. The verdict is the only judgment on a listing. Every other mark is a statement of fact.
Every listing shows a letter grade, A to F, reflecting how much trust the software has earned, and a status word describing where it stands today. The two are independent: C · Emerging is a clean project that has not yet built a reputation, while B · Caution is a widely adopted server with open findings. When multiple statuses apply, the most significant one is shown.
Deep verification, no outstanding findings, and an established reputation.
No concerning findings. Grades remain capped until the project builds reputation through adoption.
Automated analysis covers part of this stack. Findings reflect what we verified.
Specific findings reduced this grade. They are listed on the page.
Serious findings were identified. Review the full report before connecting.
Verification marks describe how far our analysis reached. They indicate method, not endorsement.
The code matches what its tools declare.
Executed in an isolated environment and its behavior observed.
Re-verified automatically on every code change.
Sustained monitored history contributes to a publisher's reputation.
Identity marks show who has claimed this listing and the level of proof behind the claim.
The publisher confirmed this listing by email.
The publisher proved control of the repository.
is-it-legit-mcp carries every mark on this page: ⚡ Live Monitored, code verified, all tools read and graded. It is our own MCP, held to the same checks as everything else in the index.