New MCP directory RepoAI scores servers on trust, auth, and dangerous tools
Low_Location1261 · reddit · 2026-07-21
- The author built repoai.io, a directory and security-scoring tool for MCP servers, after worrying about giving random MCP repos read/write access to local files or command execution.
- The site assigns a transparent Trust Score (0–100) using 15 public checks, including maintainer identity, repo activity, stars, license, dependency footprint, archive status, read-only mode, OAuth support, and the share of dangerous execute/delete/write tools.
- The author stresses that this is not a penetration test or CVE scanner; it is a public-signal-based review system with some manual and AI-assisted checks.
- They’re asking developers whether the weights make sense and what other signals should be added.
More from coding & agent
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- 105 hidden bugs, 2 repos: DeepSeek V4.1 Flash fixes 24 at $1.80 vs Opus 5's 27 at $51.33 — ChartsJournalX · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- Running the Firefox MCP on Android via Termux, ngrok, and mcp-proxy — Nervous-Strain7544 · 2026-09-11
- SmolVM open-sources persistent computer infrastructure for agents that outlive chat sessions — aniketmaurya · 2026-09-11