MCP Commons

Security

Listed means audited. Here's what that guarantee covers.

The review

Every submitted version (hosted or link-out, free or paid) runs through the same pipeline: automated scanners (dependency audit, secret detection, static egress extraction, sandbox diffing) feed their findings plus the full source and tool manifest to an AI review agent. It emits a structured report, a pass / flag / fail verdict and the human-readable data-flow summary published on each listing. Passes publish automatically; flags and fails escalate to a human.

The badge

The AI-review badge on a listing carries the review model and badge version and links to the data-flow summary for that exact version. Versions are immutable and re-reviewed on every bump. Published hosted versions are periodically re-scanned for newly disclosed CVEs.

Runtime containment

Hosted tools run with an egress allowlist pinned to their manifest, enforced at the gateway for isolates and at the network namespace for containers. Third-party API credentials are stored platform-encrypted per entitlement and injected at dispatch; they never live in tool code.

Disclosure

Found something? Email security@mcpcommons.com. We acknowledge reports within one business day, unroute affected slugs immediately as a kill switch when warranted and publish a postmortem after resolution.