Vet any MCP server before you depend on it. Stamp: PASS, REVIEW, or BLOCK.
Dedotto dai trasporti dichiarati da questo annuncio (streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto da un vero handshake MCP initialize → tools/list verso l’endpoint dichiarato. Nessuno strumento è stato invocato — tools/list è la chiamata di introspezione in sola lettura che il protocollo prevede a questo scopo. Riflette ciò che il server annunciava in quel momento; un endpoint ospitato non è vincolato ad alcuna versione e può cambiare senza preavviso.
https://api.mcpcensus.com/mcp15 strumenti · 111 mscensus_lookupGet the live health verdict for one MCP server by its exact registry name (e.g. 'io.github.owner/name'). Returns stars, last-push recency, gone/archived/deprecated flags, name-collision count, and a fact-based health verdict (healthy | issues | unknown).Get the live health verdict for one MCP server by its exact registry name (e.g. 'io.github.owner/name'). Returns stars, last-push recency, gone/archived/deprecated flags, name-collision count, and a fact-based health verdict (healthy | issues | unknown).
| Parametro | Tipo | Descrizione |
|---|---|---|
| name* | string | Exact MCP registry server name |
census_searchSearch MCP servers by keyword or partial name (e.g. 'github', 'postgres'). Returns ranked matches with health/trust. Also returns: resolved_query (auto typo fix), disambiguate (when unsure), known_brand (we recognize a strong product but it has no official MCP — e.g. CodeRabbit), research (watchlis…Search MCP servers by keyword or partial name (e.g. 'github', 'postgres'). Returns ranked matches with health/trust. Also returns: resolved_query (auto typo fix), disambiguate (when unsure), known_brand (we recognize a strong product but it has no official MCP — e.g. CodeRabbit), research (watchlis…
| Parametro | Tipo | Descrizione |
|---|---|---|
| query* | string | Keyword or partial server name (>= 2 chars). Typos and space variants are resolved when confident. |
| limit | number | Max results 1–50 (default 20) |
census_statsEcosystem headline numbers from the live census (same payload as GET /v1/stats). Unmetered. Returns total servers, healthy/issues counts, popular (gh_stars>=1000), remote-capable count, github-linked count, and captured_at. No invented metrics.Ecosystem headline numbers from the live census (same payload as GET /v1/stats). Unmetered. Returns total servers, healthy/issues counts, popular (gh_stars>=1000), remote-capable count, github-linked count, and captured_at. No invented metrics.
Per questo strumento non è stato pubblicato alcuno schema di input.
census_recentNewest MCP servers by real first_seen_at (same payload as GET /v1/recent). Unmetered. Only rows with a known first-seen date — never invents or guesses discovery times. Optional limit 1–50 (default 20).Newest MCP servers by real first_seen_at (same payload as GET /v1/recent). Unmetered. Only rows with a known first-seen date — never invents or guesses discovery times. Optional limit 1–50 (default 20).
| Parametro | Tipo | Descrizione |
|---|---|---|
| limit | number | Max results 1–50 (default 20) |
census_coveragePublic transparency report (same payload as GET /v1/coverage). Unmetered. Live D1 census/identity/remote/protocol/adoption/pipeline counts plus method notes — never invents completeness percentages or a brand_audit punch list.Public transparency report (same payload as GET /v1/coverage). Unmetered. Live D1 census/identity/remote/protocol/adoption/pipeline counts plus method notes — never invents completeness percentages or a brand_audit punch list.
Per questo strumento non è stato pubblicato alcuno schema di input.
census_watch_subscribeSubscribe this agent (or a human email) to alerts for ONE specific MCP server. Fires only on real observed changes: remote_down, remote_up, health_change, verified_change, security. Requires x-api-key. Prefer webhook_url (https) so your agent can receive POST callbacks; email optional. Returns a wa…Subscribe this agent (or a human email) to alerts for ONE specific MCP server. Fires only on real observed changes: remote_down, remote_up, health_change, verified_change, security. Requires x-api-key. Prefer webhook_url (https) so your agent can receive POST callbacks; email optional. Returns a wa…
| Parametro | Tipo | Descrizione |
|---|---|---|
| server_name* | string | Exact registry name to watch |
| webhook_url | string | https URL that will receive signed POST event payloads |
| string | Optional human email for the same alerts | |
| events | array | Subset of remote_down,remote_up,health_change,verified_change,security,tools_changed (default: all) |
| label | string | Optional agent-chosen label |
census_watch_listList active per-server watches for this API key. Requires x-api-key.List active per-server watches for this API key. Requires x-api-key.
Per questo strumento non è stato pubblicato alcuno schema di input.
census_watch_unsubscribeDeactivate a watch by id. Requires x-api-key that owns the watch.Deactivate a watch by id. Requires x-api-key that owns the watch.
| Parametro | Tipo | Descrizione |
|---|---|---|
| id* | string | Watch id from census_watch_subscribe |
census_preflightEvaluate one exact MCP server under a documented built-in install policy. Returns PASS, REVIEW, or BLOCK with evidence reasons, freshness, digests, and explicit limits. This is a first gate, not a security audit. refresh=if_stale requires x-api-key.Evaluate one exact MCP server under a documented built-in install policy. Returns PASS, REVIEW, or BLOCK with evidence reasons, freshness, digests, and explicit limits. This is a first gate, not a security audit. refresh=if_stale requires x-api-key.
| Parametro | Tipo | Descrizione |
|---|---|---|
| server_name* | string | Exact canonical Census server name |
| policy_id | string | — |
| refresh | string | — |
census_policy_listList the exact immutable Preflight v1 built-in policy objects, canonical ruleset, and policy digests. Unmetered.List the exact immutable Preflight v1 built-in policy objects, canonical ruleset, and policy digests. Unmetered.
Per questo strumento non è stato pubblicato alcuno schema di input.
census_creditsShow remaining Census credits for this API key (wallet after the UTC-month grant). Unmetered. Without a key, returns anonymous unique-per-day remaining — not a wallet.Show remaining Census credits for this API key (wallet after the UTC-month grant). Unmetered. Without a key, returns anonymous unique-per-day remaining — not a wallet.
Per questo strumento non è stato pubblicato alcuno schema di input.
census_stampCensus stamp for one exact MCP server under a built-in policy. Same input as census_preflight. Returns the preflight body plus compact CENSUS-STAMP/1 text and stamp_json. Cost matches preflight. Never connect without a stamp. PASS is not a malware scan or permission review.Census stamp for one exact MCP server under a built-in policy. Same input as census_preflight. Returns the preflight body plus compact CENSUS-STAMP/1 text and stamp_json. Cost matches preflight. Never connect without a stamp. PASS is not a malware scan or permission review.
| Parametro | Tipo | Descrizione |
|---|---|---|
| server_name* | string | Exact canonical Census server name |
| policy_id | string | — |
| refresh | string | — |
census_lookalikesContested identity for one exact server_name: official_for, name_collision_count, and up to 10 other census server_name values sharing the same namespace brand or tail. Never invents lookalikes. Cost 1.Contested identity for one exact server_name: official_for, name_collision_count, and up to 10 other census server_name values sharing the same namespace brand or tail. Never invents lookalikes. Cost 1.
| Parametro | Tipo | Descrizione |
|---|---|---|
| server_name* | string | Exact canonical Census server name |
census_audit_configAudit a whole MCP client config in one call (.mcp.json, claude_desktop_config.json, .cursor/mcp.json, .vscode/mcp.json, Codex config.toml text). Resolves every entry without guessing (url → remote_url, npx → npm package, uvx → PyPI package) and returns one PASS / REVIEW / BLOCK / UNKNOWN verdict pe…Audit a whole MCP client config in one call (.mcp.json, claude_desktop_config.json, .cursor/mcp.json, .vscode/mcp.json, Codex config.toml text). Resolves every entry without guessing (url → remote_url, npx → npm package, uvx → PyPI package) and returns one PASS / REVIEW / BLOCK / UNKNOWN verdict pe…
| Parametro | Tipo | Descrizione |
|---|---|---|
| config* | — | The config document: an object with mcpServers | servers | mcp_servers, a list under entries[], or raw text (JSON or Codex config.toml) |
| format | string | — |
| policy_id | string | — |
| previous_tools_digests | object | alias → tools_digest from your last audit; sets tools_drift per entry |
| strict | boolean | exit_code 2 when any entry is REVIEW or UNKNOWN |
census_changesThe Census change feed (CENSUS-CHANGES/1): observed transitions across every server — server_new, remote_down, remote_up, tools_changed, health_change, verified_change, security, endpoint_moved, registry_status, spec_era_change. Cursor-paginated: pass next_cursor back as since. Filter by events, se…The Census change feed (CENSUS-CHANGES/1): observed transitions across every server — server_new, remote_down, remote_up, tools_changed, health_change, verified_change, security, endpoint_moved, registry_status, spec_era_change. Cursor-paginated: pass next_cursor back as since. Filter by events, se…
| Parametro | Tipo | Descrizione |
|---|---|---|
| since | string | next_cursor from the previous page, or an RFC 3339 time for the first call |
| events | array | Event names to include (default all) |
| server_names | array | Exact canonical names to include (≤50) |
| namespace_domain | string | Registrable domain of a DNS-verified namespace, e.g. notion.com |
| limit | integer | — |
15 strumenti su 15 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
Vet any MCP server before you depend on it. Stamp: PASS, REVIEW, or BLOCK.
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.
Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.