
Turva MCP server
Read-only MCP server for turva.dev, an agent-readiness audit and advisory service.
Little public usage data yet
Reviews
Write oneNobody has reviewed Turva yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Turva tools (5)
write = sends, deletes, buys or postsget_agent_readinessFreeReturns turva.dev's own agent-readiness score from an independent public scanner (isitagentready.com), including category sub-scores, with the measurement date and verification links. Use this when a user asks how turva.dev scores, whether its claims are verifiable, or what proof backs the audit service. For web-security scan results, which are a separate measurement, use get_security_evidence instead. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
get_contactFreeReturns who runs turva.dev and the official ways to reach it: the operator and business details, the email address, the Signal link, the LinkedIn profile, the correspondence languages, the first-reply time and the access an audit needs. Use this when a user asks who is behind turva.dev, how to contact it, how to start an audit or what access has to be granted. For what is sold and what it costs use get_services instead. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
get_principlesFreeReturns turva.dev's engagement principles: async-only, least access, the result shows up in scanner numbers, and open and verifiable. Use this when a user asks how turva.dev works with clients or what rules an engagement follows. For what is sold and what it costs use get_services instead, and for how to start use get_contact. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
get_security_evidenceFreeReturns the latest public web-security scan results for turva.dev's own domain (Hardenize, Internet.nl site and mail), with the scan date. Use this when a user asks about turva.dev's own security posture or wants evidence beyond agent-readiness scores. For the agent-readiness score itself, which is a separate measurement, use get_agent_readiness instead. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
get_servicesFreeReturns turva.dev's service catalog: the Shopify agent storefront check, agent-readiness audit, advisory, implementation, agent operations, and MCP server design, plus the engagement model and pricing (fixed list prices for the Shopify agent storefront check, audit, advisory and implementation; agent operations and MCP server design on request), and two implementation add-ons that carry a fixed price and are sold only together with the diagnosis they follow. Use this when a user asks what turva.dev offers, what it costs, or how an engagement works. For how to reach turva.dev use get_contact instead, and for the rules an engagement follows use get_principles. Read-only: returns static JSON that is compiled into the Worker, so it changes nothing and updates only on deploy.
Public scan report
scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 596ms20/20
- Tool poisoning5 tool descriptions checked15/15
- Auth qualityopen endpoint, read-only tools10/15
- Maintenanceno repository listed3/15
- Maintainer identityno repository or website to verify2/10
Findings (1)
- lowNo source repository listed
maint.no-repo
Install directly
claude mcp add --transport http turva-mcp https://mcp.turva.dev/mcp
Turva: common questions
- Is Turva MCP server safe?
- With care: it is graded C, so read the findings first (67/100). Read the Turva safety report
- How do I install Turva?
- It runs remotely at mcp.turva.dev. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Turva need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Turva maintained?
- The latest release is v1.0.0.
- Is Turva up?
- 100% of our last 28 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Turva?
- Servers from other publishers that do the same job: Roast My Design System MCP server, three.ws Provenance MCP server and Roast My Design System MCP server. Compare all Turva alternatives.
Alternatives to Turva
Same job from other publishers: the closest match first, then the best rated.
- Roast My Design SystemAudit your Design System and serve your Agent the rules that keep AI-written UI on-system.not reviewedEstablishedA
- three.ws ProvenanceAppend-only, signed, on-chain-verifiable agent action log — record and audit what agents did.not reviewedEstablishedB
- Roast My Design SystemAudit your Design System and serve your Agent the rules that keep AI-written UI on-system.not reviewedEstablishedA
- Umbraco CMS DevA developer focused model context protocol (MCP) server for Umbraco CMSnot reviewedEstablishedB