mcp server
Dredd MCP
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
Description as published by the maintainer. Source
- version 1.0.0
- slowing
- security
slowing — Registry entry last updated 2026-05-04. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
1 function, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
check_mcp_server(tool, server, version)- Pre-flight security verdict for an MCP server invocation. Judges BOTH server-level reputation AND the server's dependency graph (npm/pypi) against the DugganUSA threat-intel corpus (1.13M+ IOCs, Shai-Hulud + typosquat + LOLBin families). Returns BLOCK / ADVISORY / REVIEW / ALLOW with severity, evidence, dep-graph summary, and HMAC-signed response. REVIEW means we hold NO RECORD of this server -- not that it is safe. Treat REVIEW as do-not-proceed-blindly: a brand-new attacker-published server looks exactly like this. ALLOW is only returned when we actually resolved the server and scanned its dependency graph; check known_to_us and dep_graph.scanned to confirm. Use this BEFORE invoking any other MCP server tool, especially ones installed from outside the official MCP Registry. Required: server.
Last successful function declaration observed on . Source: https://analytics.dugganusa.com/api/v1/dredd/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://analytics.dugganusa.com/api/v1/dredd/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.0.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-05-04 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-05-04 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 1 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | analytics.dugganusa.com | |
| mcp endpoint status | ok | The server listed 1 function when asked. | as of probe | analytics.dugganusa.com |
Where to get it
Also from pduggusa
-
DugganUSA CLI — Local STDIO MCP
Local STDIO MCP for DugganUSA threat intel. 1.13M IOCs. Read-only. npm: dugganusa-cli.
-
Jeevesus — DugganUSA Threat Intelligence MCP
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json