Independent trust grade B+ (87/100). No blocking issues found in the static + spec checks. wmcp.sh continuously watches mcp.tomevault.io for tool drift and rug-pulls. The grade is free and identical whether or not the operator pays.
search_tomesSearch TomeVault for agent context files (tomes, configs, skills) by a task description. Filter by format, kind, and quality grade. Returns ranked mat
get_tomeFetch one tome's content in a specific agent format (default claude_md). Every response carries the provenance verdict: quality grade, security scan g
get_provenanceReturn the signed attestation record alone for a tome: quality grade, security scan grade and flags, decay risk, source registry, the content hash it
scan_contentScan submitted instruction-file text for safety, clarity, loadability, and cross-model consistency, and return a verdict with findings. Use before loa
convert_contentConvert pasted instruction-file text into another tool's format (claude_md, agents_md, cursor_mdc, gemini_md, copilot_instructions, windsurf_rules, sk
verify_attestationVerify a TomeVault attestation document (the contents of a repo's .tome/attestation.json). Confirms the detached signature is genuinely TomeVault's ag
list_vault_itemsList the items in your TomeVault that this token can read. Requires a vault access token with the items:read scope. Encrypted (private) items are neve
get_vault_itemFetch one of your TomeVault items by id, with its content. Requires a vault access token with the items:read scope. Encrypted items are not retrievabl
No proxied traffic observed for this host yet. Connect it at /connect and its grade gains a measured Reliability score + per-tool behavioral evidence — the half a static scan can't produce.
We re-grade mcp.tomevault.io on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.
Run mcp.tomevault.io? Claim it (free) to get drift alerts and show an independently-verified trust badge. The grade stays free — claiming just ties it to you.
Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:
https://wmcp.sh/mcp/trust
readOnly vs observed behavior) layer on via the wmcp.sh proxy.