Skip to content

Add SRI to Resources - #4671

Open
SRITEST0001 wants to merge 1 commit into
modelcontextprotocol:mainfrom
SRITEST0001:patch-2
Open

Add SRI to Resources#4671
SRITEST0001 wants to merge 1 commit into
modelcontextprotocol:mainfrom
SRITEST0001:patch-2

Conversation

@SRITEST0001

Copy link
Copy Markdown

Adds SRI to the Resources list in ADDITIONAL.md.

SRI reads the published source of MCP servers and reports what they do, with
every finding anchored to a file:line and the code quoted verbatim. Findings
whose quoted evidence cannot be located in the file are dropped, so the claims
are checkable rather than asserted.

It reports observations, not verdicts — it does not certify that a server is
safe, and an empty result is not a clearance.

2,174 registry servers have been read so far. The per-category counts and the
method are published, so the numbers can be recomputed rather than trusted:
https://github.com/SRITEST0001/sri/tree/main/research

The live figures are also served as JSON, free and without a key:

curl https://sri-test.biz/v1/corpus

Checking one server, free, no key:

curl -X POST https://sri-test.biz/v1/verify \
  -H 'Content-Type: application/json' \
  -d '{"ecosystem":"mcp","name":"io.github.firebase/firebase-mcp","version":"0.3.0"}'

Also published in the MCP Registry as biz.sri-test/verifier.

Disclosure: I built and run this. It is free right now. If a finding is wrong
there is a form on the site and it will be withdrawn.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant