Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for MCP authors, platform teams, and security-minded builders who want something more concrete than checklist advice when reviewing tool permissions, prompt-injection paths, and package risk around agent integrations.
Who should use it
Who should skip it
Pass on MCP-Audit/MCTS if its scope or audience does not match what your team is building right now.
About this signal
MCP-Audit/MCTS is tracked by RepoRadar as a developer tool in the Agent Security section. First seen 2026-06-28; the source record was last checked on 2026-06-28. The current verdict is 'try now' with a Gold tier and moderate setup difficulty. The standout signals for MCP-Audit/MCTS are workflow potential (9.9) and open-source/build quality (8.4), while momentum (5.0) trails — that balance shapes where it fits best. This page summarizes the public evidence on the linked source page and states where additional review is still needed.
How this item is evaluated
The MCP-Audit/MCTS record combines a 8.4/10 composite score with separate popularity (1.0), risk (conditional), and setup (moderate) signals. See the scoring methodology for the current weights and evidence definitions.
Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.
Risk explanation
Live probing and fuzzing modes should stay on test servers or disposable sandboxes until you understand exactly which tools and integrations they exercise; The project is still labeled alpha, so teams should treat its scores as a strong audit signal rather than a substitute for manual review.