# MCP Server Trust & Security Checker

> MCP Server Trust & Security Checker is a paid API for AI agents from 47620.xyz, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Evaluates an MCP server for safety and trustworthiness by checking reachability, HTTPS, handshake, risky capabilities, and prompt-injection signals, returning a 0-100 trust score and verdict.

## Facts

- Endpoint: GET https://47620.xyz/x/mcp-trust?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/mcp-server-trust-security-checker-8cb14fa7
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_dbm_NikiQEAwcrkrz6ynd

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability mcp-server-trust-security-checker-8cb14fa7
```

Example prompt: Before I connect to that MCP server at https://some-mcp-server.example.com, can you run a trust check on it and tell me its safety score and whether it has any risky capabilities like shell or file access?

## When to prefer this

Use this endpoint when an AI agent or developer needs to vet an MCP server before connecting to it, especially for third-party or community servers where trustworthiness is unknown. It is the right choice when you need a structured, machine-readable trust verdict with specific risk signals (shell access, prompt injection) rather than a manual or ad-hoc review.

## Known failure modes

- Target MCP server is unreachable — returns low trust score with reachability failure finding
- Target URL is malformed or missing — returns error response
- MCP handshake fails — flagged in findings with reduced trust score
- Payment not included or insufficient — x402 payment required error
- Rate limiting or timeout on slow target servers — may return partial findings

## How this service works

MCP SERVER TRUST / SECURITY CHECK: verify BEFORE connecting whether an MCP server is safe to trust — reachability, MCP handshake, HTTPS, advertised tools, risky capabilities (shell/file/exec) and prompt-injection / tool-poisoning signals — returning a 0-100 trust score, verdict (trusted/review/do-not-trust) and findings. Pass ?target=<mcp-url> to check a specific server (defaults to a live demo server).

## Output

Returns a JSON object containing a 0-100 numeric trust score, a verdict string (trusted, review, or do-not-trust), detailed findings covering reachability, HTTPS validation, MCP handshake result, advertised tools inventory, flagged risky capabilities (shell/file/exec), and any detected prompt-injection or tool-poisoning signals.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {
      "fields": {
       "type": "string",
       "description": "Optional comma-separated top-level response keys to keep (e.g. \"health,slot,solUsd\"). Omit for the full payload."
      }
     },
     "additionalProperties": false
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type",
    "example"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "json"
    },
    "example": {
     "type": "object",
     "required": [
      "ok",
      "endpoint"
     ],
     "properties": {
      "ok": {
       "type": "boolean"
      },
      "endpoint": {
       "type": "string"
      }
     },
     "additionalProperties": true
    }
   },
   "additionalProperties": false
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/mcp-server-trust-security-checker-8cb14fa7/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from 47620.xyz](https://www.zero.xyz/host/47620.xyz/llms.txt)
