trustcard: MCP Server Security and Usability Scanner
Middle_Lecture7302 · reddit · 2026-07-15
A developer has built an MCP server scanning tool called mcp-trustcard, functioning much like npm audit. It runs 8 checks (including installation, protocol handshake, tool schema validity, destructive tools, authentication, secret exposure, protocol version, and latency) and generates a score out of 100.
Core Findings: Testing on 10 popular MCP servers revealed that 4 failed the protocol handshake due to hidden environment variables or parameters undiscoverable by the client. Furthermore, server-github is still using an outdated protocol.
The author also proposed introducing a standard mcp.health metadata field in the registry, allowing clients to read the trust card before connecting and avoiding post-connection debugging.
Related event: mcp-trustcard: Security Scoring Tool for MCP Servers(2 posts)→
More from coding & agent
- Inspired by OpenAI's 10,000-agent run, dev open-sources a crowdsourced agent problem-solving platform — Benjaminsen · 2026-09-11
- Lucid: open-source Mac app keeps your laptop awake only while AI agents run — Pitiful_Hedgehog_600 · 2026-09-11
- banteg's snail project crowdsources AI agents to finish matching Snail Mail's 20 remaining functions — banteg · 2026-09-11
- Alex Townsend posts 200 open problems in numerical linear algebra for humans and AI agents — IgorCarron · 2026-09-11
- Kimi K2.8 Preview rolls out: near-K3 coding performance, 1M context for all tiers — teortaxesTex · 2026-09-11
- Looking for a classifier of software engineering task shapes to pick models per task — StewartalsopIII · 2026-09-11