Stillos Ratings Mcp

io.github.stillmarcus24v1.0.0更新於 Oct 5, 2026

Check an MCP server before you install it — outside-in trust ratings for 7,000+ operators.

概覽

AI 產生的概覽

讓助手在安裝前查詢 MCP 伺服器主機的第三方信任評等與工具介面發現。

功能
透過公開評等普查提供三個工具:check_mcp_server 回傳單一主機的等級、排名、五個評分面向、發布者與機群集中度,以及任何帶日期的發現;list_tool_surface_findings 列出目前帶有帶日期工具介面發現的營運者;compare_mcp_servers 最多並列比較 10 個候選。回答包含 fleet 區塊與附重算連結的收據雜湊。主要訊號是版本字串未變但工具介面已改變。
適用情境
適合在決定是否安裝或信任某個遠端 MCP 伺服器時使用,或在把某個主機加入用戶端前比較多個候選。這是安裝前檢查,不是稽核,也不是安全認證。
執行需求
以 stdio 在本機執行,通常透過 npx,需要 Node.js 以及連線至評等端點的網路。未宣告金鑰、註冊、帳號、環境變數或標頭。
安裝前請注意
評等是受測群體內的百分位排名,不是安全認證。未評等主機會回傳 NOT_RATED,沒有發現也不等於健康證明;未被觀測不等於已被證明安全。涵蓋範圍有限,缺少某主機並不代表該營運者有問題。查詢會把主機名稱傳送到第三方端點。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Stillos Ratings Mcp,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

stillos-ratings-mcp

Check an MCP server before you install it.

Installing an MCP server means handing a stranger's code a tool surface inside your client. There is no standard way to ask "should I?" — this is one. It answers from a public census of 7,000+ MCP operators, refreshed every 6 hours, rated from the outside, unasked, the way a credit bureau rates a borrower rather than the way a badge rates whoever applied for it.

Free. No key, no signup, no account. Every figure is independently recomputable.

bash
npx stillos-ratings-mcp check api.mcp.ainpx stillos-ratings-mcp findingsnpx stillos-ratings-mcp compare api.mcp.ai some-other-host.com

As an MCP server

json
{  "mcpServers": {    "stillos-ratings": { "command": "npx", "args": ["-y", "stillos-ratings-mcp", "mcp"] }  }}

Tools

ToolWhat it answers
check_mcp_serverGrade, rank, five scored dimensions, rail position, publisher/fleet concentration, and any dated finding for one host
list_tool_surface_findingsEvery operator currently carrying a dated tool-surface finding
compare_mcp_serversUp to 10 candidates side by side

What a finding actually means

The headline signal is a tool surface that changed while the version string did not.

Two anonymous tools/list enumerations of the same endpoint, at different times. The serverInfo.version string was byte-identical in both. The tool set was not. Any client that pinned that version and approved its tool list was never asked to re-approve what it now exposes — and if one of the added tools takes an action (writes, sends, moves money, deletes), that matters.

This is an observation about change. It is not an accusation of malice, and this tool will never phrase it as one.

One of a fleet, or one someone built?

The public registry is far more concentrated than it looks. Measured 2026-10-04 across 39,321 registry entries from 23,281 publishers: the top 10 publishers control 19.0% of it, one GitHub account alone publishes 2,365 servers, and 34.8% of tool-bearing servers share a boilerplate tool set with a template fleet — while 20,980 publishers have exactly one server.

So every answer carries a fleet block: who publishes it, how many servers that publisher has, and how many others share its core tool set. A server that is 1 of 1,022 running the same template is a different proposition from a one-off, and that was the most decision-relevant fact nobody was reporting.

It is a structural observation about how a server was produced — not an accusation of bad faith, and a large publisher can still ship good software. Where the registry does not cover a host, the block says concentration was not measured, which is deliberately not the same sentence as "not a fleet".

What this is not

  • Not an audit. A grade is percentile standing within the measured population, not a security certification. The whole ecosystem scores low on these dimensions today.
  • Not a pass when a host is missing. An unrated host returns NOT_RATED with an explicit warning. We enumerate 41.8% of the distinct remote-declaring hosts in the public registry (measured, as of 2026-10-04) — so absence is a statement about our reach, not about that operator. Unobserved is not attested safe.
  • Not a clean bill of health when there is no finding. It means we did not observe that specific failure mode on that host.
  • Not self-reported. No operator supplies its own numbers, and no operator can change its grade by asking us.

Disputing a number

Recompute it. The board is sealed and public, the method is published in full, and the dimensions are arithmetic over a public census — so there is no judgement call to argue with and no appeal to make to us.

  • Method: https://stillosdigitalholdings.com/ratings/methodology
  • Any operator's record: https://stillosdigitalholdings.com/ratings/n/<host>
  • Verify a receipt: https://stillosdigitalholdings.com/notary/verify?hash=<receipt_hash> — every check_mcp_server answer carries the receipt_hash and a ready-made link in its recompute block (live example). Scope is integrity and timestamp only — it proves the board you are reading is the board that was sealed, not that any rating is "correct".

Data source

GET https://stillosdigitalholdings.com/ratings/node?host=<host> — free and unmetered. This package is a thin client over that endpoint, holds no credential, and can therefore leak none. Every answer it gives can be reproduced with curl.

MIT · Still OS Digital Holdings LLC, Wyoming

來源:README.md,提交 be57f14

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 5, 2026