Know before you connect.
A security registry for every MCP server, with a composite 0 to 100 trust score from eleven signals and per-version scanning, all recorded with cryptographic provenance so you know what you are connecting to before you connect.
Crawl. Scan. Score. Sign.
Ledger continuously indexes the major public MCP registries, scans each version for prompt injection, secrets, and known CVEs, verifies tool annotations against observed behavior, and signs every score with Sigstore in an append-only transparency log the Hub consults for the servers you connect to.
Composite 0 to 100 trust score
Eleven signals, from permission scope and author reputation to spec compliance and vulnerability history, roll up into one score you can compare at a glance.
Every version, scanned
Each indexed version is scanned for prompt injection across the full schema, hardcoded secrets, dependency CVEs, command injection, and unicode obfuscation.
Annotations, verified
Declared tool annotations are checked against observed behavior and surfaced as verified, unverified, or mismatch, so a read-only tool that writes is caught.
Signed and logged
Every score is signed with Sigstore and recorded in an append-only transparency log, so an auditor can verify it was produced by Ultra at the stated time.
Search any server, see its score.
Browse trust scores across the registry, filter by score, registry, and risk level, and open any server for its grade, per-signal breakdown, tool inventory, version history, and provenance chain before you connect it.
Trust & Verify.
Search any MCP server and see its trust score and security details before connecting.
Know what your agents connect to.
Join the waitlist to get early access to Ultra's AI-native security and governance.