trustcard: MCP Server Security and Usability Scanner
Middle_Lecture7302 · reddit · 2026-07-15
A developer has built an MCP server scanning tool called `mcp-trustcard`, functioning much like npm audit. It runs 8 checks (including installation, protocol handshake, tool schema validity, destructive tools, authentication, secret exposure, protocol version, and latency) and generates a score out of 100. **Core Findings**: Testing on 10 popular MCP servers revealed that 4 failed the protocol handshake due to hidden environment variables or parameters undiscoverable by the client. Furthermore, server-github is still using an outdated protocol. The author also proposed introducing a standard `mcp.health` metadata field in the registry, allowing clients to read the trust card before connecting and avoiding post-connection debugging.
Related event: mcp-trustcard: Security Scoring Tool for MCP Servers(2 posts)→
More from coding & agent
- The author says Codex reached 20x and is now debugging spec decoding on a hybrid parallel setup — TheZachMueller · 2026-07-21
- Axcess adds an MCP connector for WCAG accessibility checks that scanners miss — modelcontextprotocol · 2026-07-21
- X post asks whether Cursor Composer, built on Kimi models, would also be banned — max_paperclips · 2026-07-21
- A developer’s Codex usage is draining pooled enterprise credits at a small company — Distinct_Relation_62 · 2026-07-21
- Qwen Code ships cua-driver-rs 0.7.3 with relative coordinates and MCP filtering — github-actions[bot] · 2026-07-21
- Matt Pocock says every new codebase turns legacy within days — mattpocockuk · 2026-07-21