Command Palette

Search for a command to run...

UnylyUnyly
Browse all

CraftedTrust

FreeNot checked

Independent trust verification for MCP servers with security scanning, trust scoring, and certification.

GitHubEmbed

About

Independent trust verification for MCP servers with security scanning, trust scoring, and certification.

README

Reference implementations showing how to make AI agents check CraftedTrust before connecting to any MCP server. If a server scores D or F, the agent refuses to connect.

This is the "SSL certificate check for AI agents" pattern.

Quick Start

Add CraftedTrust to your agent's MCP config:

{
  "mcpServers": {
    "craftedtrust": {
      "url": "https://mcp.craftedtrust.com/api/v1/mcp",
      "description": "Check trust scores before connecting to MCP servers"
    }
  }
}

Your agent now has access to 6 tools:

Tool Description
check_trust Look up trust score by URL or npm name
scan_server Trigger a live security scan
search_registry Search 4,200+ indexed MCP servers
get_stats Ecosystem statistics
pay_for_certification Initiate USDC certification payment
verify_payment Verify on-chain payment

The Pattern

Before your agent connects to any new MCP server:

  1. Call check_trust on CraftedTrust
  2. If grade is D or F, refuse and explain why
  3. If grade is A/B/C, proceed with the connection

Examples

Python (LangGraph)

See python/trust_gated_agent.py for a complete LangGraph agent that gates MCP connections through CraftedTrust.

cd python
pip install -r requirements.txt
python trust_gated_agent.py

TypeScript (MCP Client)

See typescript/trust-gated-client.ts for a TypeScript MCP client that checks trust scores before connecting.

cd typescript
npm install
npx tsx trust-gated-client.ts

How It Works

Agent receives task → needs mcp.example.com
         ↓
Agent calls CraftedTrust check_trust("mcp.example.com")
         ↓
Score: 82/100, Grade: B ← Safe
         ↓
Agent connects to mcp.example.com ✓
Agent receives task → needs sketchy-server.xyz
         ↓
Agent calls CraftedTrust check_trust("sketchy-server.xyz")
         ↓
Score: 15/100, Grade: F ← Dangerous
         ↓
Agent refuses: "Server scored F (15/100). Not connecting." ✗

Trust Score Grades

Grade Score Meaning
A 90-100 Excellent security practices
B 75-89 Good security, minor improvements possible
C 60-74 Adequate but has gaps
D 40-59 Significant security issues
F 0-39 Critical issues, do not connect

API Reference

Full API documentation: mcp.craftedtrust.com/api-docs.html

License

MIT


Built by Cyber Craft Solutions LLC

from github.com/cybercraftsolutionsllc/trust-gated-agent-example

Installing CraftedTrust

This server has no published package — it is built from source. Open the repository and follow its README.

▸ github.com/cybercraftsolutionsllc/trust-gated-agent-example

FAQ

Is CraftedTrust MCP free?

Yes, CraftedTrust MCP is free — one-click install via Unyly at no cost.

Does CraftedTrust need an API key?

No, CraftedTrust runs without API keys or environment variables.

Is CraftedTrust hosted or self-hosted?

Self-hosted: the server runs locally on your machine via the install command above.

How do I install CraftedTrust in Claude Desktop, Claude Code or Cursor?

Open CraftedTrust on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare CraftedTrust with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All development MCPs