Server identity, package source, update path, and tool manifest are reviewed before first use.
MCP Trust Verification Generator
Build a non-sensitive review checklist for an MCP server or tool bundle before an AI agent can use it in a real workflow.
Copyable trust plan
Use this in an issue, PR, launch note, or internal acceptance checklist after review.
What this protects
Mutating tools ask before use. Read-only output cannot silently widen approvals later.
Receipts stay non-sensitive: policy id, action class, decision, rationale, and rollback owner.
This public page runs fully in the browser and does not submit, save, track, store, or send data. It is a planning aid, not legal advice, compliance certification, penetration testing, incident response, or a security guarantee.