Trustcard
Cryptographic trust infrastructure for MCP servers — content-addressed tool identity, signed manifests, TOFU pinning, capability descriptors, a two-gate invocation policy, signed+chained receipts, and publisher key rotation. Also the "npm audit" health-ch
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability
Category: Security — see all ranked ›
Install (Claude Code):
claude mcp add trustcard -- npx -y mcp-trustcard- tashan score: 57.0
- Adoption: 177/wk
- Upkeep: 66.0
- Freshness: 93.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
npm ↗ · source ↗ · pkg:mcp-trustcard
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›
Measured 2026-08-08 · scorer s5 · how · something wrong here?