Add SRI to Resources - #4671
Open
SRITEST0001 wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds SRI to the Resources list in ADDITIONAL.md.
SRI reads the published source of MCP servers and reports what they do, with
every finding anchored to a file:line and the code quoted verbatim. Findings
whose quoted evidence cannot be located in the file are dropped, so the claims
are checkable rather than asserted.
It reports observations, not verdicts — it does not certify that a server is
safe, and an empty result is not a clearance.
2,174 registry servers have been read so far. The per-category counts and the
method are published, so the numbers can be recomputed rather than trusted:
https://github.com/SRITEST0001/sri/tree/main/research
The live figures are also served as JSON, free and without a key:
Checking one server, free, no key:
Also published in the MCP Registry as biz.sri-test/verifier.
Disclosure: I built and run this. It is free right now. If a finding is wrong
there is a form on the site and it will be withdrawn.