Install payload
Install payload is broadly covered in current results.
100% (12/12)
Source-backed filter active — add entries to compare trust side by side.
Trust signals across 40 of 142 results
3 trust signals differ in this sample: Review status, Source provenance, Submitter
Signals differ on Review status, Source provenance, Submitter — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
100% (12/12)
Most at-risk entries in this view
Adoption queue
17/142 visible results are in hold tier and need mitigation before adoption.
No required blockers for this preset.
64/100
Collect package checksum or signed artifact information.
mcp/contrastapi-mcp-server · trust review · confidence 83%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/dependency-risk-review · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/incident-timeline · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/pr-security-review · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/ai-adeu-adeu-mcp-server · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/agent-skills-cross-platform-adapter-capability-pack · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/agenttrust-identity-and-trust-for-a2a-agents-mcp-server · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/aws-sns-sqs-mcp-server · trust review · confidence 67%
Decision confidence
17/142 results are low-confidence and need review before adoption.
Address Package integrity before broader rollout.
68/100
mcp/contrastapi-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/dependency-risk-review · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/incident-timeline · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/pr-security-review · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/ai-adeu-adeu-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/agent-skills-cross-platform-adapter-capability-pack · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/agenttrust-identity-and-trust-for-a2a-agents-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/aws-sns-sqs-mcp-server · trust review
Freshness distribution
Median age 42 days; 11 fresh, 1 aging or stale of 12 scanned.
Oldest entries in this view
Theme distribution
118 distinct themes with no dominant one. Most common: security, capability-pack, mcp.
118 distinct themes across 24 scanned
49 remote MCP security tools for CVE/KEV/CWE/EPSS lookup, composite CVSS+EPSS+KEV+PoC risk scoring, CVSS v3.x vector parsing, domain/IP/IOC enrichment, dependency and web intelligence checks, MITRE ATLAS AI/ML attacks, and MITRE D3FEND defenses. Anonymous tier available; Pro tier uses an API key.
The official Codacy MCP server (@codacy/codacy-mcp) that gives AI assistants access to the Codacy API for code quality, security, and coverage — listing repository and pull-request issues, retrieving file coverage and duplication, searching security (SRM) findings, inspecting analysis tools and patterns, and running local analysis with the Codacy CLI.
Independent community library of 754 cybersecurity Agent Skills mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF for defensive security analysis, incident response, forensics, cloud security, SOC operations, and governed red-team workflows.
Microsoft open-source course for learning AI agents with lessons on agentic frameworks, design patterns, tool use, agentic RAG, trustworthy agents, planning, multi-agent systems, MCP/A2A/NLWeb, memory, browser use, and Microsoft Agent Framework.
Microsoft open-source Model Context Protocol curriculum with hands-on MCP server, client, security, transport, auth, deployment, Azure, VS Code, Inspector, PostgreSQL, and cross-language examples.
WordPress contributor-reviewed Agent Skills for AI coding assistants working on Gutenberg blocks, block themes, plugins, REST APIs, Interactivity API, Abilities API, WP-CLI, Playground, performance, PHPStan, and directory rules.
Expert GitHub Actions security review capability pack applying documented workflow hardening, GITHUB_TOKEN least privilege, secrets handling, and fork PR safety checks from official GitHub Actions security documentation.
Community reusable agent prompt for reviewing new MCP server adoption in Claude Code using official security documentation: trusted providers, permissions configuration, trust verification, and settings checked into source control.
Slash command that reviews a pull request diff for security regressions: authentication and authorization gaps, injection surfaces, secret exposure, unsafe deserialization, and dependency risk introduced by the change.
Expert MCP remote server trust review capability pack for auditing OAuth flows, transport security, tool permissions, data exfiltration risk, and vendor scope before connecting Claude Code to third-party MCP servers.
Official SonarSource MCP server that connects Claude to SonarQube Server or SonarQube Cloud for code quality, security issues, hotspots, measures, quality gates, branches, pull requests, snippets, and system context.
Offensive security MCP framework that connects AI agents to a large toolkit for authorized penetration testing, vulnerability discovery, CTF, OSINT, and security research workflows.
Apache-2.0 CNCF-incubating Kubernetes security platform and CLI for scanning clusters, manifests, Helm charts, Kustomize projects, Git repositories, and container images for misconfigurations, compliance gaps, and vulnerabilities.
Official Snyk Studio MCP Server for connecting Claude Code, Codex CLI, Cursor, Gemini CLI, and other local MCP clients to Snyk Code, Open Source, IaC, container, SBOM, AI-BOM, package-health, authentication, and secure-at-inception workflows.
Official AWS Labs MCP server for Amazon SNS and SQS that lets AI assistants list and manage SNS topics, subscriptions, and SQS queues and send/receive messages, with resource tagging so it only modifies what it created.
Safety-reviewed Agent Skill for Hermes Tweet, the Hermes Agent plugin for X/Twitter endpoint discovery, credentialed reads, and approval-gated actions through Xquik.
MIT-licensed BrowserAct Agent Skill pack for installing and operating the `browser-act` browser automation CLI from Claude Code, Codex, OpenClaw, Cursor, OpenCode, Windsurf, Gemini CLI, and other skills-compatible agents.
Expert Claude Code Chrome browser QA capability pack applying documented Claude in Chrome enablement, browser automation boundaries, and web QA checkpoint workflows.
Community reusable agent prompt for end-to-end GUI validation with Claude Code computer use using official documentation: enable the computer-use MCP server, per-app session approval, screenshot checkpoints, and documented example workflows for native apps.
SpotDB local MCP server that exposes an ephemeral DuckDB sandbox for AI agents to upload CSV data, run guarded SQL queries, and explore datasets without touching production databases.
Expert incident timeline reconstruction capability pack for correlating deploy events, logs, traces, alerts, and chat transcripts into a source-backed, privacy-safe post-incident timeline with validation checkpoints.
Expert maintainer pull request triage capability pack for classifying open PRs, applying labels, routing reviewers, checking merge readiness, and producing privacy-safe queue summaries using GitHub pull request documentation workflows.
AgentTrust stdio MCP server giving AI agents verified identity with email, instant messaging, and cloud file storage across 19 Ed25519-signed tools.
Expert subagent foreground background delegation capability pack for choosing when to run Claude Code subagents interactively versus in the background, coordinating parallel work, and returning summarized results safely.
Expert Claude Code deep links runbook capability pack for building safe claude-cli:// URLs, embedding them in incident runbooks, and validating cwd, repo, and prompt parameters before users press Enter.
MCP server for Odoo ERP systems, with tools for reading records, discovering models and fields, aggregating data, diagnosing access, scanning addons, planning migrations, and running gated safe-write workflows.
Source-backed agent for reviewing Atlas database schema migrations with migration lint, analyzers, drift detection, CI/CD evidence, dev-database simulation, rollout risk, rollback planning, and production safety gates.
MCP server that gives Claude DuckDuckGo web search plus webpage content fetching and parsing tools.
Source-backed agent for reviewing local-first Jupyter notebook workflows that use Jupytext text notebooks, paired notebooks, command-line sync, and version-control friendly reproducibility checks.
Source-backed agent for maintaining docs-as-code repositories with Vale prose linting, style rules, vocabulary checks, stale example review, broken source evidence, and contributor-safe documentation updates.