C

npm:@unfragile/mcp-server

https://www.npmjs.com/package/@unfragile/mcp-server
75/100 · MCP Trust Grade · checked 2h ago · MCP 0.7.0

What it offers — 15 tools · Developer Tools

unfragile_resolve

RESOLVE an agent intent into the single best AI artifact to invoke, with an invocation-ready snippet, a cryptographically signed trust passport, and a

search

Search the Unfragile match graph for AI tools, frameworks, APIs, MCP servers, agents, and more. Returns ranked results with capability matches and gra

find_mcps

Find MCP servers by capability need. Use this when you need to discover MCP servers for specific integrations (e.g., databases, APIs, cloud services).

get_artifact

Get full details and capabilities for a specific AI artifact by name or slug. Uses search-based lookup (best-effort name matching — may return a diffe

resolve_capability

Resolve a capability:// URI or natural-language capability into ranked AI artifacts. This is Unfragile

trust_passport

Get the machine-readable trust passport for an AI artifact. Use this before an agent selects a tool, API, MCP server, model, repo, or framework for a

unfragile_verify

Verify a tool / MCP server / package BEFORE invoking or installing it. Returns a signed verdict: trusted | caution | unverified | flagged. Pass the in

compare

Compare two AI artifacts side-by-side. Shows capabilities, pricing, rank, and graph signals for each. Uses search-based lookup (best-effort name match

find_stack

Assemble a complete AI harness stack for a use case. Given a description of what you

feedback

Report whether a tool actually worked AFTER you invoked it. This closes the learning loop — outcomes are how the Unfragile graph stays accurate and im

subscribe

Set up a persistent watch for new AI tools matching a query. Get notified daily when something new appears in the Unfragile graph. Requires at least o

unfragile_validate

Validate an unfragile.yml manifest against the Unfragile Capability Protocol v1. Returns the structured validation result with errors, warnings, and t

unfragile_passport

Fetch the raw machine-readable trust passport for an artifact by slug (trust_passport_v1 schema). Returns JSON suitable for programmatic policy checks

unfragile_resolve_capability

Resolve a

unsubscribe

Cancel a persistent watch (monitor). Use the monitor ID returned from subscribe.

Spec / packaging20%100
Security (OWASP MCP)30%25
Maintenance / popularity20%100
Tool hygiene15%95
Transparency / provenance15%90

Findings

WARNMCP08 References sensitive file paths / environment secrets.
INFO Static analysis of npm package @unfragile/mcp-server@0.7.0 (stdio server — no remote endpoint). Reliability/behavioral signals require running it; not measured.
Grade another server

We re-grade npm:@unfragile/mcp-server on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.

Share this report card

A 1200×630 card with the grade + audit — drop it in a post, Slack, or your repo.

MCP Trust report card — npm:@unfragile/mcp-server grade C
Share on X Open card image

Embed this grade

A live badge — it re-verifies itself and shows current stability. Static scorecards can't. Paste it in your README or site to show users you're independently audited.

MCP Trust Grade C · wmcp.sh
[![MCP Trust Grade C](https://wmcp.sh/mcp/grade/npm%3A%40unfragile%2Fmcp-server/badge.svg)](https://wmcp.sh/mcp/grade/npm%3A%40unfragile%2Fmcp-server)
<a href="https://wmcp.sh/mcp/grade/npm%3A%40unfragile%2Fmcp-server"><img src="https://wmcp.sh/mcp/grade/npm%3A%40unfragile%2Fmcp-server/badge.svg" alt="MCP Trust Grade C · wmcp.sh"></a>

Agents: check this before connecting

Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:

https://wmcp.sh/mcp/trust
How this grade is computed. An open, independent rubric — Spec conformance (20%), Security mapped to the OWASP MCP Top 10 (30%), Reliability (20%), Tool hygiene (15%), Transparency (15%) — run by connecting to the server and inspecting its real MCP surface. The grade is free and identical whether or not the operator pays. v1 uses static + spec signals from a single connection; continuous uptime, real latency, and annotation-truthing (declared readOnly vs observed behavior) layer on via the wmcp.sh proxy.