{
  "data": {
    "tool": {
      "category": "",
      "endpoint": "https://api.policylayer.com/mcp",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/policylayer-registry.json",
      "kind": "mcp",
      "listed": "indexed",
      "liveUrl": "https://www.anchorterminal.com/api/v1/live/policylayer-registry.json",
      "markdownUrl": "https://www.anchorterminal.com/tools/policylayer-registry.md",
      "mcpTools": {
        "check": {
          "checker": "anchor-check/1.0",
          "totalTokens": 927,
          "counts": {
            "error": 0,
            "note": 1,
            "warn": 5
          },
          "findings": [
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "check_mcp_server",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "check_mcp_stack",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "check_tool",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_change_events",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "search_registry",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"search\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC24",
              "severity": "note",
              "message": "5 of 5 tools have no outputSchema",
              "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
            }
          ]
        },
        "checkedAt": "2026-10-04T22:23:34Z",
        "count": 5,
        "schemaTokens": 927,
        "status": "ok",
        "tools": [
          {
            "name": "check_mcp_server",
            "description": "Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk grade, auth posture, freshness, and the tool surface listed riskiest-first. A server the registry does not know is queued for scanning by this very call — check back shortly.",
            "inputSchema": {
              "properties": {
                "server": {
                  "description": "Registry slug, npm package name (e.g. @acme/mcp-server), remote URL, or server name.",
                  "type": "string"
                }
              },
              "required": [
                "server"
              ],
              "type": "object"
            }
          },
          {
            "name": "check_mcp_stack",
            "description": "Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdict (attention signals and a suggested action) — and the lookup status for every miss; counts, grades and flagged tools come from the published records only. Costs one rate-limit unit per server.",
            "inputSchema": {
              "properties": {
                "servers": {
                  "description": "One entry per server in the stack.",
                  "items": {
                    "properties": {
                      "candidates": {
                        "description": "Identifiers to try in order: npm package name, registry slug, or remote URL. Most package-like first.",
                        "items": {
                          "type": "string"
                        },
                        "maxItems": 5,
                        "type": "array"
                      },
                      "name": {
                        "description": "Your label for this server (e.g. its config key) — echoed back on the result.",
                        "type": "string"
                      }
                    },
                    "required": [
                      "candidates"
                    ],
                    "type": "object"
                  },
                  "maxItems": 25,
                  "type": "array"
                }
              },
              "required": [
                "servers"
              ],
              "type": "object"
            }
          },
          {
            "name": "search_registry",
            "description": "Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand) and tool count — follow up with check_mcp_server on the match you meant.",
            "inputSchema": {
              "properties": {
                "limit": {
                  "description": "Max matches to return (1-20, default 10).",
                  "type": "number"
                },
                "query": {
                  "description": "Substring to match against slug, name and packages.",
                  "type": "string"
                }
              },
              "required": [
                "query"
              ],
              "type": "object"
            }
          },
          {
            "name": "check_tool",
            "description": "One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. \"should execute_sql on this server be permitted?\"",
            "inputSchema": {
              "properties": {
                "server": {
                  "description": "Registry slug or npm package name of the server.",
                  "type": "string"
                },
                "tool": {
                  "description": "Tool name as the server declares it.",
                  "type": "string"
                }
              },
              "required": [
                "server",
                "tool"
              ],
              "type": "object"
            }
          },
          {
            "name": "get_change_events",
            "description": "The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at https://policylayer.com/registry/pricing.",
            "inputSchema": {
              "properties": {
                "after_id": {
                  "description": "Return events with id greater than this cursor (default 0).",
                  "type": "number"
                },
                "limit": {
                  "description": "Max events (1-1000, default 200).",
                  "type": "number"
                },
                "severity": {
                  "description": "Minimum severity: that level and above.",
                  "enum": [
                    "info",
                    "notice",
                    "warning",
                    "critical"
                  ],
                  "type": "string"
                }
              },
              "type": "object"
            }
          }
        ]
      },
      "name": "registry",
      "note": "Indexed from the official MCP registry: facts and our own checks, not reviewed, so no score, grade or rank.",
      "packages": null,
      "pageJsonUrl": "https://www.anchorterminal.com/tools/policylayer-registry.json",
      "popularity": {
        "githubStars": 2
      },
      "registryName": "com.policylayer/registry",
      "remotes": [
        {
          "type": "streamable-http",
          "url": "https://api.policylayer.com/mcp"
        }
      ],
      "repository": "https://github.com/PolicyLayer/mcp",
      "reviewed": false,
      "slug": "policylayer-registry",
      "source": "the official MCP registry",
      "sourceUrl": "https://registry.modelcontextprotocol.io/v0.1/servers?search=com.policylayer/registry",
      "summary": "The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.",
      "updatedAt": "2026-07-08T20:10:36Z",
      "url": "https://www.anchorterminal.com/tools/policylayer-registry",
      "vendor": "policylayer.com",
      "vendorUrl": "https://policylayer.com/registry/mcp",
      "version": "1.0.1",
      "websiteUrl": "https://policylayer.com/registry/mcp",
      "where": "hosted",
      "why": [
        "vendor"
      ]
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/policylayer-registry",
    "json": "https://www.anchorterminal.com/tools/policylayer-registry.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/policylayer-registry.md",
    "slim": "https://www.anchorterminal.com/tools/policylayer-registry.min.md"
  },
  "markdown": "# registry\n\n\u003e Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/\n\n- Kind: MCP server, by policylayer.com (https://policylayer.com/registry/mcp)\n- Listed because: It's published in the registry under policylayer.com, a namespace the registry only gives to whoever proves they control that domain.\n- What the official MCP registry says: The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.\n\n## Facts\n\n- MCP registry: `com.policylayer/registry` 1.0.1\n- Endpoint: https://api.policylayer.com/mcp (streamable HTTP)\n- Source: https://github.com/PolicyLayer/mcp\n- Website: https://policylayer.com/registry/mcp\n- GitHub stars: 2\n- Registry entry updated: 2026-07-08\n\n## Tools\n\n- Tools it lists (5, about 927 tokens of context, `tools/list` without credentials over MCP 2025-11-25, checked 2026-10-04 22:23 UTC):\n  - `check_mcp_server`: Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote…\n  - `check_mcp_stack`: Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug,…\n  - `search_registry`: Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence…\n  - `check_tool`: One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the…\n  - `get_change_events`: The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a…\n- How its tools read to an agent (0 errors, 5 warnings, 1 note, about 927 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score):\n  - warn TC16 check_mcp_server: no readOnlyHint or destructiveHint\n  - warn TC16 check_mcp_stack: no readOnlyHint or destructiveHint\n  - warn TC16 check_tool: no readOnlyHint or destructiveHint\n  - warn TC16 get_change_events: no readOnlyHint or destructiveHint\n  - warn TC16 search_registry: no readOnlyHint or destructiveHint\n  - note TC24 server: 5 of 5 tools have no outputSchema\n\n- JSON: https://www.anchorterminal.com/api/v1/tools/policylayer-registry.json\n- Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Indexed",
        "url": "https://www.anchorterminal.com/indexed/"
      },
      {
        "name": "registry",
        "url": ""
      }
    ],
    "description": "registry, an MCP server by policylayer.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.",
    "facts": [
      "not reviewed",
      "not ranked",
      "facts only"
    ],
    "h1": "registry",
    "image": "https://www.anchorterminal.com/assets/og/indexed.png",
    "path": "/tools/policylayer-registry",
    "published": "",
    "section": "indexed",
    "title": "registry: MCP server, indexed from the official MCP registry",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/tools/policylayer-registry"
  },
  "tokens": {
    "markdown": 850,
    "slim": 780
  },
  "version": 1
}
