MCPLookup MCP
MCP serverSecurityFind out whether a tool is trustworthy before your AI starts using it. This app looks up independent trust ratings and the security, maintenance, and adoption evidence behind the tools your AI could add, so you can make an informed choice.
Available today. Use it from your connected AI after setup.
No other account needed.
After adding it, ask your AI to check a tool by name. It will return the trust rating along with the supporting evidence.
Then ask your AI: use MCPLookup MCP to resolve server
What your AI can do with it
- Look up independent trust ratings for a tool
- See security evidence for a tool
- Check how well a tool is maintained
- Review evidence of how widely a tool has been adopted
From the project's README
As published by mcplookupdev/mcplookup-mcp in README.md.
The official stdio compatibility wrapper for the MCPLookup remote MCP server—the independent trust layer for MCP.
The canonical server is https://mcplookup.com/mcp. It provides three anonymous,
read-only tools:
resolve_serverresolves a title, package, endpoint, or name to a canonical server.find_serversfinds up to five servers using MCPLookup's normalized taxonomy.trust_lookupreturns the current Trust Index, verdict, evidence, and citation.
This package exists for MCP clients that require a local stdio command. It forwards MCP messages to the canonical hosted server without implementing scoring, storing evidence, adding authentication, or changing tool results.
Connect
Connect directly when your client supports remote Streamable HTTP:
https://mcplookup.com/mcp
Use this package when your client requires a local stdio command:
Node.js 20 or newer is required. No API key or environment variable is needed.
npx -y @mcplookup/mcp
Generic MCP client configuration:
{
"mcpServers": {
"mcplookup": {
"command": "npx",
"args": ["-y", "@mcplookup/mcp"]
}
}
}
Prefer a direct Streamable HTTP connection to https://mcplookup.com/mcp when your client
supports remote MCP servers. The package is a transport adapter, not a separate service.
MCP Registry
MCPLookup is listed in the official MCP Registry as
com.mcplookup/mcp.
The name is verified through DNS control of mcplookup.com.
One entry covers both connection paths, so a client installing from the Registry can use whichever it supports:
| Path | Declaration |
|---|---|
| Canonical remote | streamable-http → https://mcplookup.com/mcp |
| Compatibility package | npm @mcplookup/mcp, stdio transport |
The entry declares no environment variables, headers, or credentials, matching the
anonymous public interface. server.json in this repository is the source
of that metadata.
What stays remote
The wrapper contains no trust scores, evidence database, taxonomy, authentication system, or scoring logic. MCPLookup evaluates public evidence at the canonical service and returns the same bounded, current-state response whether a client connects directly or through this stdio adapter.
The MIT license covers the plugin and wrapper software in this repository only. It does not license MCPLookup's hosted evidence database, assessments, verdicts, scores, classifications, taxonomy, historical record, or scoring framework. Use of service data remains governed by the MCPLookup terms.
Data and security
The wrapper has no credentials and writes no local data. Requests are sent to MCPLookup's hosted endpoint, where bounded security and product telemetry are processed under the MCPLookup privacy policy. See the MCP documentation for the public interface contract.
Report security issues according to SECURITY.md. For product support, email hello@mcplookup.com.
Bug reports and narrowly scoped compatibility improvements are welcome. See CONTRIBUTING.md before opening a pull request.
Development
npm test
npm pack --dry-run
The package intentionally has zero runtime dependencies.
Marketplace package
This repository also contains the shared MCPLookup marketplace package:
.claude-plugin/plugin.jsonand.mcp.jsonpackage the remote server for Claude..codex-plugin/plugin.jsonpackages the same remote server for ChatGPT and Codex.skills/verify-mcp-server/SKILL.mdadds the proactive pre-connect verification workflow.review/marketplace-cases.mddefines the positive, negative, and direct-connect release cases.
The skill improves orchestration but is not required for correct tool selection. Direct MCP, Registry, npm-wrapper, and VS Code clients receive independently useful tool descriptions and server instructions from the canonical hosted service.
Tools it offers (3)
What this server listed when ahel dialed its public endpoint in Sep 2026, with no key and no account of yours. The names are the server’s own.
resolve_serverfind_serverstrust_lookup
Signals
- Last commit
- Aug 2026
Advanced
- Delivery
- mcp MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
- Catalog kind
- mcp-server
- Gateway key
com-mcplookup-mcp- Source
- github.com/mcplookupdev/mcplookup-mcp
- Hosted endpoint
https://mcplookup.com/mcp