Back to Directory/Security & Auth

MCPLookup

Look up independent trust ratings and security, maintenance, and adoption evidence for MCP servers.

Security & AuthJavaScriptv0.1.6

MCPLookup MCP

npm tests license MCPLookup Trust Index: gold, 89 out of 100

The official stdio compatibility wrapper for the MCPLookup remote MCP server—the independent trust layer for MCP.

The canonical server is https://mcplookup.com/mcp. It provides three anonymous, read-only tools:

  • resolve_server resolves a title, package, endpoint, or name to a canonical server.
  • find_servers finds up to five servers using MCPLookup's normalized taxonomy.
  • trust_lookup returns the current Trust Index, verdict, evidence, and citation.

This package exists for MCP clients that require a local stdio command. It forwards MCP messages to the canonical hosted server without implementing scoring, storing evidence, adding authentication, or changing tool results.

Connect

Connect directly when your client supports remote Streamable HTTP:

https://mcplookup.com/mcp

Use this package when your client requires a local stdio command:

Node.js 20 or newer is required. No API key or environment variable is needed.

npx -y @mcplookup/mcp

Generic MCP client configuration:

{
  "mcpServers": {
    "mcplookup": {
      "command": "npx",
      "args": ["-y", "@mcplookup/mcp"]
    }
  }
}

Prefer a direct Streamable HTTP connection to https://mcplookup.com/mcp when your client supports remote MCP servers. The package is a transport adapter, not a separate service.

MCP Registry

MCPLookup is listed in the official MCP Registry as com.mcplookup/mcp. The name is verified through DNS control of mcplookup.com.

One entry covers both connection paths, so a client installing from the Registry can use whichever it supports:

PathDeclaration
Canonical remotestreamable-http → https://mcplookup.com/mcp
Compatibility packagenpm @mcplookup/mcp, stdio transport

The entry declares no environment variables, headers, or credentials, matching the anonymous public interface. server.json in this repository is the source of that metadata.

What stays remote

The wrapper contains no trust scores, evidence database, taxonomy, authentication system, or scoring logic. MCPLookup evaluates public evidence at the canonical service and returns the same bounded, current-state response whether a client connects directly or through this stdio adapter.

The MIT license covers the plugin and wrapper software in this repository only. It does not license MCPLookup's hosted evidence database, assessments, verdicts, scores, classifications, taxonomy, historical record, or scoring framework. Use of service data remains governed by the MCPLookup terms.

Data and security

The wrapper has no credentials and writes no local data. Requests are sent to MCPLookup's hosted endpoint, where bounded security and product telemetry are processed under the MCPLookup privacy policy. See the MCP documentation for the public interface contract.

Report security issues according to SECURITY.md. For product support, email hello@mcplookup.com.

Bug reports and narrowly scoped compatibility improvements are welcome. See CONTRIBUTING.md before opening a pull request.

Development

npm test
npm pack --dry-run

The package intentionally has zero runtime dependencies.

Marketplace package

This repository also contains the shared MCPLookup marketplace package:

  • .claude-plugin/plugin.json and .mcp.json package the remote server for Claude.
  • .codex-plugin/plugin.json packages the same remote server for ChatGPT and Codex.
  • skills/verify-mcp-server/SKILL.md adds the proactive pre-connect verification workflow.
  • review/marketplace-cases.md defines the positive, negative, and direct-connect release cases.

The skill improves orchestration but is not required for correct tool selection. Direct MCP, Registry, npm-wrapper, and VS Code clients receive independently useful tool descriptions and server instructions from the canonical hosted service.

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @mcplookup/mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "com-mcplookup-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@mcplookup/mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@mcplookup/mcpnpm

Compatible MCP Clients

MCPLookup works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More