Not reviewed
No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
Facts
- MCP registry
com.policylayer/registry· 1.0.1- Endpoint
https://api.policylayer.com/mcp- Website
- policylayer.com/registry/mcp
- GitHub stars
- 2
- Registry entry
- updated 8 Jul 2026
From the official MCP registry, the package registries and our own checks. JSON · Markdown
Why it's listed
- It's published in the registry under policylayer.com, a namespace the registry only gives to whoever proves they control that domain.
Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.
Tools it lists 5 · about 927 tokens of context · checked 28 minutes ago
| Tool | What it does | Hint |
|---|---|---|
check_mcp_server | Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full… | |
check_mcp_stack | Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns… | |
search_registry | Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to… | |
check_tool | One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a… | |
get_change_events | The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry… |
What https://api.policylayer.com/mcp answered to tools/list, asked without credentials over MCP 2025-11-25. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.
How its tools read to an agent 0 errors · 5 warnings · 1 note
- warnTC16check_mcp_serverno readOnlyHint or destructiveHint
- warnTC16check_mcp_stackno readOnlyHint or destructiveHint
- warnTC16check_toolno readOnlyHint or destructiveHint
- warnTC16get_change_eventsno readOnlyHint or destructiveHint
- warnTC16search_registryno readOnlyHint or destructiveHint
- noteTC24server5 of 5 tools have no outputSchema
The checks from /check and anchor check, run each day on the list above: about 927 tokens of definitions. Not part of the score yet. Check your own server.