Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
"Jeevesus saves. Dredd judges." Dredd MCP is a pre-invocation security check for the Model Context Protocol ecosystem. Before your agent calls a tool on any other MCP server, Dredd renders a verdict: , , or . Every verdict is HMAC-signed and cites the IOC or behavioral signal that drove the decision. The MCP ecosystem has had no defender. Three PyPI ML packages were compromised in eight days…
Dedotto dai trasporti dichiarati da questo annuncio (streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Forge non ha completato alcun handshake tools/list verso questo endpoint, quindi non ha alcuna osservazione di ciò che il server espone. Nulla di tutto ciò dice che non esponga nulla.
"Jeevesus saves. Dredd judges." Dredd MCP is a pre-invocation security check for the Model Context Protocol ecosystem. Before your agent calls a tool on any other MCP server, Dredd renders a verdict: , , or . Every verdict is HMAC-signed and cites the IOC or behavioral signal that drove the decision. The MCP ecosystem has had no defender. Three PyPI ML packages were compromised in eight days during late April 2026. Twenty-plus MCP-named GitHub repositories were caught serving SmartLoader…