New MCP directory RepoAI scores servers on trust, auth, and dangerous tools

Low_Location1261 · reddit · 2026-07-21

- The author built **repoai.io**, a directory and security-scoring tool for MCP servers, after worrying about giving random MCP repos read/write access to local files or command execution. - The site assigns a transparent **Trust Score (0–100)** using 15 public checks, including maintainer identity, repo activity, stars, license, dependency footprint, archive status, read-only mode, OAuth support, and the share of dangerous execute/delete/write tools. - The author stresses that this is **not** a penetration test or CVE scanner; it is a public-signal-based review system with some manual and AI-assisted checks. - They’re asking developers whether the weights make sense and what other signals should be added.

Original post →

More from coding & agent

coding & agent channel →