TrustNotch MCP server
Tamper-evident audit logs for AI agents: submit, fetch, and verify cryptographic proof bundles.
C58/100grade C
Adoption
New
Little public usage data yet
Reviews
Write oneNobody has reviewed TrustNotch yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
TrustNotch tools (1, 1 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
submit_logwrite actionSubmit a tamper-evident log entry to TrustNotch.
Public scan report
scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it
no findings
- Code scan3 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancerepository not readable: unknown3/15
- Maintainer identityverified namespace with website, no repo4/10
Overall 58/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
claude mcp add trustnotch-mcp -- uvx trustnotch-mcp
TrustNotch: common questions
- Is TrustNotch MCP server safe?
- With care: it is graded C, so read the findings first (58/100). Read the TrustNotch safety report
- How do I install TrustNotch?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does TrustNotch need an API key?
- Yes. The registry entry asks for
TRUSTNOTCH_API_KEY. - Is TrustNotch maintained?
- The latest release is v0.1.1.