Atlas / MCP servers / attestd-io / attestd-mcp

attestd-mcpSAFE

mcp/attestd-io/attestd-mcp

Official MCP server for Attestd. Use Attestd supply chain and CVE signals directly in Claude Code, Cursor, and Windsurf.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@attestd/mcp) [](https://smithery.ai/server/@attestd/mcp)

Attestd checks whether a dependency version has exploitable CVEs or a confirmed supply-chain compromise. One API call returns a structured risk response.

Official Model Context Protocol (MCP) server for Attestd. Exposes CVE risk and supply-chain checks as tools for Claude Code, Claude Desktop, and any MCP-compatible client.

Get a free API key · Full docs

  • stdio transport: run via npx -y @attestd/mcp with no global install.
  • `check_package_vulnerability`: wraps `GET /v1/check` using `@attestd/sdk`.
  • `check_batch_vulnerabilities`: checks up to 100 packages in one call. Use for lockfile and manifest audits.
  • `list_covered_products`: returns Attestd-covered products. With an API key, returns live data from GET /v1/products. Without a key, returns the static bundled infrastructure list.
  • `get_cve_details`: returns CVSS, EPSS, KEV status, and affected products for a single CVE id.
  • `get_usage`: returns remaining quota for the authenticated key (GET /v1/usage).

Prerequisites

  • Node.js 18+
  • An Attestd API key from the portal. Required for check_package_vulnerability, check_batch_vulnerabilities, get_cve_details, get_usage, and live list_covered_products.

Claude Code / MCP config

Add to ~/.claude/mcp.json or project .mcp.json:

{
"mcpServers": {
"attestd": {
"command": "npx",
"args": ["-y", "@attestd/mcp"],
"env": {
"ATTESTD_API_KEY": "your-api-key-here"
}
}
}
}

Optional: ove

Read from source at commit d546d0d3a058OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp --env ATTESTD_API_KEY=${ATTESTD_API_KEY} -- npx -y @attestd/[email protected]
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@attestd/sdk, @modelcontextprotocol/sdk, @types/node, tsup, typescript, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d546d0d3a058full audit observations/trust-audit/mcp-server/attestd-io__attestd-mcp.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d546d0d3a058SAFEB89first audit
05

Questions

What is the attestd-mcp MCP server?

Official MCP server for Attestd. Use Attestd supply chain and CVE signals directly in Claude Code, Cursor, and Windsurf.

Is attestd-mcp safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does attestd-mcp need?

It reads ATTESTD_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does attestd-mcp run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @attestd/mcp at 0.3.2.

How current is this page?

The grade is for one exact copy of the source (d546d0d3a058), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement