# registry > registry, an MCP server by policylayer.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install. - Canonical: https://www.anchorterminal.com/tools/policylayer-registry - Markdown: https://www.anchorterminal.com/tools/policylayer-registry.md (~850 tokens) - Slim: https://www.anchorterminal.com/tools/policylayer-registry.min.md (~780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/policylayer-registry.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 # registry > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by policylayer.com (https://policylayer.com/registry/mcp) - Listed because: It's published in the registry under policylayer.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install. ## Facts - MCP registry: `com.policylayer/registry` 1.0.1 - Endpoint: https://api.policylayer.com/mcp (streamable HTTP) - Source: https://github.com/PolicyLayer/mcp - Website: https://policylayer.com/registry/mcp - GitHub stars: 2 - Registry entry updated: 2026-07-08 ## Tools - Tools it lists (5, about 927 tokens of context, `tools/list` without credentials over MCP 2025-11-25, checked 2026-10-04 22:23 UTC): - `check_mcp_server`: Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote… - `check_mcp_stack`: Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug,… - `search_registry`: Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence… - `check_tool`: One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the… - `get_change_events`: The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a… - How its tools read to an agent (0 errors, 5 warnings, 1 note, about 927 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC16 check_mcp_server: no readOnlyHint or destructiveHint - warn TC16 check_mcp_stack: no readOnlyHint or destructiveHint - warn TC16 check_tool: no readOnlyHint or destructiveHint - warn TC16 get_change_events: no readOnlyHint or destructiveHint - warn TC16 search_registry: no readOnlyHint or destructiveHint - note TC24 server: 5 of 5 tools have no outputSchema - JSON: https://www.anchorterminal.com/api/v1/tools/policylayer-registry.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming