Stillos Ratings Mcp

io.github.stillmarcus24v1.0.0Updated Oct 5, 2026

Check an MCP server before you install it — outside-in trust ratings for 7,000+ operators.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant look up outside-in trust ratings and tool-surface findings for MCP server hosts before installing them.

What it does
Provides three tools over a public ratings census: check_mcp_server returns a grade, rank, five scored dimensions, publisher and fleet concentration, and any dated finding for one host; list_tool_surface_findings lists operators with a dated tool-surface finding; compare_mcp_servers puts up to 10 candidates side by side. Answers include a fleet block and a receipt hash with a recompute link. The headline signal is a tool surface that changed while the version string did not.
When to use it
Useful when deciding whether to install or trust a remote MCP server, or when comparing several candidate hosts before adding one to a client. It is a pre-install check, not an audit or a security certification.
Requirements
Runs locally over stdio, typically via npx, and needs Node.js and network access to the ratings endpoint. No key, signup, account, environment variables or headers are declared.
Before you install
Ratings are percentile standing within a measured population, not a security certification. An unrated host returns NOT_RATED, and absence of a finding is not a clean bill of health; unobserved is not attested safe. Coverage is partial, so a missing host says nothing about that operator. Queries send the host name to a third-party endpoint.

Installation

In SourceWeft

  1. Open Stillos Ratings Mcp in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

stillos-ratings-mcp

Check an MCP server before you install it.

Installing an MCP server means handing a stranger's code a tool surface inside your client. There is no standard way to ask "should I?" — this is one. It answers from a public census of 7,000+ MCP operators, refreshed every 6 hours, rated from the outside, unasked, the way a credit bureau rates a borrower rather than the way a badge rates whoever applied for it.

Free. No key, no signup, no account. Every figure is independently recomputable.

bash
npx stillos-ratings-mcp check api.mcp.ainpx stillos-ratings-mcp findingsnpx stillos-ratings-mcp compare api.mcp.ai some-other-host.com

As an MCP server

json
{  "mcpServers": {    "stillos-ratings": { "command": "npx", "args": ["-y", "stillos-ratings-mcp", "mcp"] }  }}

Tools

ToolWhat it answers
check_mcp_serverGrade, rank, five scored dimensions, rail position, publisher/fleet concentration, and any dated finding for one host
list_tool_surface_findingsEvery operator currently carrying a dated tool-surface finding
compare_mcp_serversUp to 10 candidates side by side

What a finding actually means

The headline signal is a tool surface that changed while the version string did not.

Two anonymous tools/list enumerations of the same endpoint, at different times. The serverInfo.version string was byte-identical in both. The tool set was not. Any client that pinned that version and approved its tool list was never asked to re-approve what it now exposes — and if one of the added tools takes an action (writes, sends, moves money, deletes), that matters.

This is an observation about change. It is not an accusation of malice, and this tool will never phrase it as one.

One of a fleet, or one someone built?

The public registry is far more concentrated than it looks. Measured 2026-10-04 across 39,321 registry entries from 23,281 publishers: the top 10 publishers control 19.0% of it, one GitHub account alone publishes 2,365 servers, and 34.8% of tool-bearing servers share a boilerplate tool set with a template fleet — while 20,980 publishers have exactly one server.

So every answer carries a fleet block: who publishes it, how many servers that publisher has, and how many others share its core tool set. A server that is 1 of 1,022 running the same template is a different proposition from a one-off, and that was the most decision-relevant fact nobody was reporting.

It is a structural observation about how a server was produced — not an accusation of bad faith, and a large publisher can still ship good software. Where the registry does not cover a host, the block says concentration was not measured, which is deliberately not the same sentence as "not a fleet".

What this is not

  • Not an audit. A grade is percentile standing within the measured population, not a security certification. The whole ecosystem scores low on these dimensions today.
  • Not a pass when a host is missing. An unrated host returns NOT_RATED with an explicit warning. We enumerate 41.8% of the distinct remote-declaring hosts in the public registry (measured, as of 2026-10-04) — so absence is a statement about our reach, not about that operator. Unobserved is not attested safe.
  • Not a clean bill of health when there is no finding. It means we did not observe that specific failure mode on that host.
  • Not self-reported. No operator supplies its own numbers, and no operator can change its grade by asking us.

Disputing a number

Recompute it. The board is sealed and public, the method is published in full, and the dimensions are arithmetic over a public census — so there is no judgement call to argue with and no appeal to make to us.

  • Method: https://stillosdigitalholdings.com/ratings/methodology
  • Any operator's record: https://stillosdigitalholdings.com/ratings/n/<host>
  • Verify a receipt: https://stillosdigitalholdings.com/notary/verify?hash=<receipt_hash> — every check_mcp_server answer carries the receipt_hash and a ready-made link in its recompute block (live example). Scope is integrity and timestamp only — it proves the board you are reading is the board that was sealed, not that any rating is "correct".

Data source

GET https://stillosdigitalholdings.com/ratings/node?host=<host> — free and unmetered. This package is a thin client over that endpoint, holds no credential, and can therefore leak none. Every answer it gives can be reproduced with curl.

MIT · Still OS Digital Holdings LLC, Wyoming

Source: README.md at commit be57f14

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 5, 2026