New MCP directory RepoAI scores servers on trust, auth, and dangerous tools
Low_Location1261 · reddit · 2026-07-21
- The author built repoai.io, a directory and security-scoring tool for MCP servers, after worrying about giving random MCP repos read/write access to local files or command execution.
- The site assigns a transparent Trust Score (0–100) using 15 public checks, including maintainer identity, repo activity, stars, license, dependency footprint, archive status, read-only mode, OAuth support, and the share of dangerous execute/delete/write tools.
- The author stresses that this is not a penetration test or CVE scanner; it is a public-signal-based review system with some manual and AI-assisted checks.
- They’re asking developers whether the weights make sense and what other signals should be added.
More from coding & agent
- Dev builds interactive 3D product experience with GPT-6 Astra + Hyper3D Rodin — nikola_mr64990 · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11