trustmcp is an open-source command-line scanner for Model Context Protocol servers. It performs static SAST checks, dynamic live analysis, and authentication-posture assessment, then produces A–F scores and SARIF output for GitHub Security workflows.
trustmcp sits in PulseGate's Security & compliance platforms category. It focuses on assessing MCP server security and authentication posture without manually reviewing code or live behavior. trustmcp is an open-source project aimed at developers and security engineers building or auditing MCP servers. The project is open source (MIT). It ships for the command line, and it can be self-hosted.
v0idw4lker builds and maintains trustmcp, and it first shipped in 2026. The project is developed in the open on GitHub with 6 commits in the last 90 days. Among its 6 catalogued features are static analysis, dynamic scanning, and auth analysis. It exposes integrations via an MCP server.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do