scan_packageScan an npm package for MCP security issues. Checks install scripts, prompt injection patterns, suspicious URLs, source code patterns, dependency coun
get_verdictGet a trust verdict for an MCP package: allow, warn, or block. Based on scan findings (score and severity). Also reports monitoring status and publish
check_exposureCheck which monitored MCP servers depend on a given package. Use this during incident response to find blast radius. Example:
check_abuseCheck if a package or agent has been reported to the KYA abuse database. Returns whether abuse has been reported and any details.
monitor_statusCheck if an MCP package is under continuous monitoring and get its scan history. Shows current score, risk level, and recent changes.
check_my_repoInspect the current repo for MCP dependencies, look up AgentScore verdicts for each package, and summarise what should be gated in CI. Use this when a
generate_policy_gate_setupGenerate the exact GitHub Actions workflow needed to enforce AgentScore Policy Gate for a repo. Detects MCP dependencies locally and returns the YAML,
install_policy_gateWrite the AgentScore Policy Gate workflow file to this repo. Creates .github/workflows/agentscore-policy-gate.yml with OIDC authentication (no API key
We re-grade npm:@agentscore-xyz/mcp-server on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.
Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:
https://wmcp.sh/mcp/trust
readOnly vs observed behavior) layer on via the wmcp.sh proxy.