Mmcp.market

trustlists MCP server

by trustlists·io.github.trustlists/mcp·v0.2.1

Find public vendor trust centers, browse listed frameworks, and map project dependencies.

A91/100grade A
What users say
No reviews yet
Be the first
Safety scan
A91/100

full report

Adoption
Growing

0 stars30 downloads/wk

Reviews

Write one

Nobody has reviewed trustlists yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

trustlists tools (4)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • trustlists_audit_dependencies

    Scan a project's dependency manifests (package.json, requirements.txt, go.mod, Cargo.toml, Gemfile, composer.json, pyproject.toml, Pipfile) and map likely vendors to public trust center records. Returns documentation-visibility data, not a security score. Use when inventorying third-party services or preparing vendor review.

  • trustlists_browse

    Browse the public trustlists directory by exact trust center platform, listed framework, or CSA STAR level. Use for questions like "show SafeBase-hosted vendors", "find entries listing ISO 27001", or "list CSA STAR Level 2 companies". Results are directory metadata, not security ratings.

  • trustlists_lookup

    Look up one company in the public trustlists directory by exact website domain. Returns its trust center URL, platform, listed frameworks, CSA STAR level, verification date, and directory page. Directory metadata is a discovery aid, not proof of compliance.

  • trustlists_search

    Search thousands of public trust center records by company name or website domain. Returns directory matches with trust center URLs, platforms, listed frameworks, CSA STAR levels, and source pages. Use when the user gives a company name or partial domain.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

no findings
  • Code scan13 source files scanned25/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 21 days ago15/15
  • Maintainer identityregistry namespace matches repository owner7/10
Overall 91/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

Runs npx -y @trustlists/mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add mcp -- npx -y @trustlists/mcp
Add to Cursor

trustlists: common questions

Is trustlists MCP server safe?
Yes, by our scan: it is graded A (91/100). Read the trustlists safety report
How do I install trustlists?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does trustlists need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is trustlists maintained?
The last commit was 22 days ago (2026-08-30). The latest release is v0.2.1.
What can I use instead of trustlists?
Servers from other publishers that do the same job: Vendor Status MCP server, CityAlert MCP server and Repo Graph MCP server. Compare all trustlists alternatives.

Alternatives to trustlists

Same job from other publishers: the closest match first, then the best rated.

All trustlists alternatives →
  • Vendor Status
    Status-page map for 1,100+ SaaS/cloud vendors plus 15,700+ incidents. No API key.
    C
  • CityAlert
    Free live public-safety incident map: global crime, fire, disaster, weather and news feeds
    C
  • Repo Graph
    Structural graph map of any codebase so LLMs navigate by structure, not guesswork.
    A
  • Aviation Weather
    Fetch METARs, TAFs, PIREPs, and domestic SIGMETs from the NWS Aviation Weather Center.
    A
  • France Data
    French public-data MCP: cross-ref health, demographics, business, geo & real-estate.
    A

More from trustlists