New MCP directory RepoAI scores servers on trust, auth, and dangerous tools
Low_Location1261 · reddit · 2026-07-21
- The author built **repoai.io**, a directory and security-scoring tool for MCP servers, after worrying about giving random MCP repos read/write access to local files or command execution. - The site assigns a transparent **Trust Score (0–100)** using 15 public checks, including maintainer identity, repo activity, stars, license, dependency footprint, archive status, read-only mode, OAuth support, and the share of dangerous execute/delete/write tools. - The author stresses that this is **not** a penetration test or CVE scanner; it is a public-signal-based review system with some manual and AI-assisted checks. - They’re asking developers whether the weights make sense and what other signals should be added.
More from coding & agent
- uv-scripts/ocr returns to the top of Hugging Face datasets with a JSON model picker — vanstriendaniel · 2026-07-21
- Sonar CEO says a guide-verify-solve loop cuts coding-agent issues by 92% — alex_verem · 2026-07-21
- A creator built an Awwwards-style landing page with ChatGPT 5.6 Sol in one conversation — paw_lean · 2026-07-21
- OpenAI’s Build Week buildathon drew 40 people for 11 hours with Codex — paw_lean · 2026-07-21
- Workshop to cover loop and graph engineering for AI-native software engineering — Al_Grigor · 2026-07-21
- Production agents may need a new PaaS layer built around audit and recovery — percoAi · 2026-07-21