Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for teams that want a concrete security layer between MCP tools and their agents instead of trusting every tool response by default.
Who should use it
Who should skip it
Move on from vaultmcp/vault if the licensing terms, language support, or platform requirements do not fit your project.
About this signal
vaultmcp/vault is tracked by RepoRadar as a mcp security proxy in the AI Infrastructure section. It was first seen on 2026-06-30 and last updated on 2026-06-30. The current verdict is 'try now' with a Gold tier and moderate setup difficulty. Across RepoRadar's eight signals, vaultmcp/vault is strongest on workflow potential (9.4) and practical usefulness (9.0) and weakest on momentum (6.0) — a profile worth weighing against your own priorities. This page summarizes the evidence RepoRadar has captured from captured source metadata. The score, tier, risk label, and verdict on this page are never influenced by sponsorship, ads, or tips — they reflect only the usefulness, popularity, novelty, momentum, maturity, and evidence signals described in the RepoRadar methodology.
How this item is evaluated
RepoRadar assigned vaultmcp/vault a composite score of 8.3 out of 10, placing it in the Gold tier. This score combines weighted sub-signals: usefulness (35%), novelty (18%), momentum (14%), maturity (10%), open-source/build quality (7%), evidence quality (6%), workflow potential (6%), and setup ease (4%). Popularity is tracked separately at 1.0 and never affects the composite score or tier. The risk label of 'conditional' reflects inherent user-impacting hazards, not generic novelty. Items with no risk flag may still require normal code review before production use.
Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.
Risk explanation
Layer 3 can forward tool-response content to an external model backend, so sensitive MCP output should stay on approved local or explicitly governed routes; Offline mode skips the deepest model-backed scan, so teams should benchmark detection coverage before treating it as a hard security boundary.
