METHODOLOGY · VERSION 2.0

Evidence before confidence.

Our ratings separate source claims from independent verification. Every score is attached to evidence, a methodology version, and a point in time.

01

Discover

Normalize listings from registries, repositories, packages, and endpoints into canonical MCP implementations.

02

Verify

Check package existence, executable entrypoints, SDK usage, transports, launch instructions, and endpoint behavior.

03

Version

Store immutable releases, integrity hashes, dependencies, Git mappings, tool schemas, and material changes.

04

Assess

Score security posture, blast radius, maintenance, provenance, usability, exposure, and data quality separately.

05

Scan

Run controlled, reproducible tests. Link every result to an exact package version or remote observation.

06

Monitor

Detect new releases, changed capabilities, endpoint drift, fixes, regressions, and affected version ranges.

Our language matters.

“No tested issue found” is not “guaranteed safe.” Unknown evidence stays unknown. Security signals are not vulnerabilities until independently confirmed.