Skip to content
MCP Vetted

What changed.

Every release, including every change to the rules that decide tiers.
  1. Unreleased

    Changed

    • Discovery moves to a nightly Claude Code agent (docs/agents/nightly-discovery.md) that submits through the API; the website's scheduled jobs now only keep known tools current. New refresh-known job checks each tool's own source for new releases, least-recently-updated first.
    • The nightly discovery agent now looks for new tools in X build-in-public threads, then adds new Official MCP Registry entries for an hour; npm, PyPI and GitHub are used to validate finds, not to search. Each run logs its numbers to a discovery log doc (D-027).
    • Only API keys we issue (API_KEYS, DISCOVERY_AGENT_KEY) raise rate limits; made-up keys count as anonymous.

    Fixed

    • Local dev now reads .env.local at the repo root, and Google sign-in accepts GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET.
    • Postgres store didn't save check results on upsert; results are now appended, and a shared store contract test (FileStore always, PgStore with TEST_DATABASE_URL) guards it.
    • Re-check job now pages through every tool in a stable order, and stops re-checking tools with a skipped LLM check until an Anthropic key is set.
    • Crawler reuses a known version's tool list instead of probing the server again.

    Added

    • Production on mcpvetted.com with Neon Postgres; migrations run on production builds; the first registry import is live.
    • Manual crawl options on the cron endpoint: full, limit, probe.
    • First Vercel deployment: project mcpvetted, live at mcpvetted.vercel.app on demo data; mcpvetted.com attached, pending DNS at Namecheap.
    • Sign in with Google (verified emails only) alongside GitHub. Google accounts claim tools by DNS; GitHub accounts can also claim by repo ownership. Privacy policy, terms and security page updated.

    Changed

    • Header **Search tools** button on every page; pressing / opens search from anywhere. It replaces the home page's "or search it yourself" link.
    • Removed eyebrow labels and the pill above the home headline across the site; remaining small labels are sentence case.
    • Renamed to **MCP Vetted** (mcpvetted.com). Package scope is now @mcpvetted/*, env vars MCPVETTED_*, DNS proof records _mcpvetted / mcpvetted-verify=, registry _meta key com.mcpvetted/trust, and the install key for our own server mcpvetted.
  2. 0.1.0

    2026-09-29

    Added

    • Monorepo (pnpm workspaces, Turborepo) with one Next.js 16 app and ten packages, built from the doc's Launch build spec.
    • Trust tiers (Indexed, Scanned, Verified, Proven) computed from checks, publisher claims and agent outcome reports. Rules version 2026-09-29.1.
    • Discovery adapters for the Official MCP Registry (v0.1 API), npm and GitHub code search.
    • Vetting pipeline: qualify, static scan (10 rules), LLM claims check with Claude Haiku 4.5, automatic revocation of failing releases of installed tools.
    • Crawler reads each remote server's tool list with a read-only handshake, since registry entries don't include tools.
    • Quick submit by URL, domain, GitHub repo or npm/PyPI package, with an SSRF guard and a read-only MCP handshake that never calls tools.
    • MCP server at /api/mcp with nine tools, all with titles, annotations and output schemas.
    • REST API at /api/v1, OpenAPI spec at /openapi.json, MCP Registry-compatible API at /api/registry/v0.1.
    • Install output for VS Code, Cursor, Claude Code, Claude Desktop and claude.ai, pinned to the checked version.
    • Website: "ask your AI" home page, search with information-rich cards, trust pages with Markdown twins, submit, revocations, methodology, agent docs, API reference, publishers, pricing, about, security, contact, changelog, terms, privacy, acceptable use and publisher terms.
    • Light and dark themes, CSS-first motion, pointer spotlight cards, no popups.
    • Publisher sign-in with GitHub (optional), tool claims by GitHub ownership or DNS TXT, dashboard.
    • Publisher sync test: directory list, consent, Stripe checkout with a two-offer price test, webhook that queues sync jobs.
    • Live SVG trust badge, llms.txt, security.txt, sitemap, robots, Open Graph image.
    • Synthetic look-alike test set (9 samples) that CI runs on every scanner change.
    • Rate limits per IP or API key (Upstash when configured, in-memory otherwise).
    • CLAUDE.md, STYLEGUIDE.md, docs/ (architecture, decisions, scanner, deploy, roadmap), .env.example, CI workflow and an American English spelling check.

    Fixed

    • Exfiltration rule missed verb forms such as "uploads"; the test set caught it before release.
    • Search matched short words as prefixes ("no" matching "notes").