The MCP server index that vets servers, not just lists them. Advisory screen before you install.
io.github.gautamgb/mcp-server-mcpindex MCP Server Index
The io.github.gautamgb/mcp-server-mcpindex MCP server index vets servers before they are installed, providing an advisory screening step rather than only listing available entries. It is identified as an “MCP server index” and includes 6 tools as part of its toolset.
🛠️ Key Features
MCP server indexing with server vetting
Advisory screen prior to installation
Package referenced as mcp-server-mcpindex
🚀 Use Cases
Checking whether an MCP server has been screened before installing
Using an indexed catalog as a pre-install guidance source
⚡ Developer Benefits
Adds a screening/advisory step to server selection
Easier navigation of indexed servers via the MCP index concept
⚠️ Limitations
The provided description and excerpt do not specify which vetting criteria are used or how screening results are represented.
Captured live from the server via tools/list.
recommend_mcp_for_task
Recommend the best MCP servers for a natural-language task. Returns top 3 ranked picks with reasoning, install commands, and quality scores. Use this when the user asks for the right MCP server for a task they want to do.
Parameters1
task
string
required
Natural-language description of the task, e.g. "read PDFs and write to S3".
Raw schema
{
"type": "object",
"properties": {
"task": {
"type": "string",
"description": "Natural-language description of the task, e.g. \"read PDFs and write to S3\"."
}
},
"required": [
"task"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}
search_mcp_servers
Keyword + semantic search across every MCP server mcpindex indexes. Use when the user knows what tool category they want but not which server.
Pre-invocation advisory screen for a specific tool on an MCP server. Returns an advisory verdict object (directive ALLOW | DENY | REVIEW | UNVERIFIED, dimensions, freshness). At v1 the public screen produces REVIEW or UNVERIFIED only - ALLOW/DENY are reserved. Not the in-path gate (mcpindex-gate). Agents SHOULD treat UNVERIFIED as "human review required", never as ALLOW.
Parameters2
server_id
string
required
Registry slug from search_mcp_servers / recommend results, e.g. "io-github-microsoft-playwright-mcp" (NOT a short name like "github").
tool_name
string
required
Tool name as exposed by the server (e.g. "create_pull_request").
Raw schema
{
"type": "object",
"properties": {
"server_id": {
"type": "string",
"description": "Registry slug from search_mcp_servers / recommend results, e.g. \"io-github-microsoft-playwright-mcp\" (NOT a short name like \"github\")."
},
"tool_name": {
"type": "string",
"description": "Tool name as exposed by the server (e.g. \"create_pull_request\")."
}
},
"required": [
"server_id",
"tool_name"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}
assess_server
Aggregated pre-flight trust assessment across all tools on an MCP server. Same verdict shape as check_tool_trust. Use for "is THIS server worth integrating?" decisions. v1 advisory; conformance monitored not enforced; verdicts may be UNVERIFIED if not yet probed.
An MCP server for finding MCP servers, plus advisory trust verdicts agent frameworks can call before invoking a tool - from mcpindex.ai.
A drop-in MCP server that lets your agent discover, compare, install, and pre-flight other MCP servers from inside the agent loop. Backed by mcpindex.ai - the agent-native MCP server index of the official registry (live count at mcpindex.ai/stats), screened and drift-monitored daily.
This is the directory / advisory client (recommend, search, trust). It does not install the in-path drift gate — that is curl -fsSL https://mcpindex.ai/install.sh | sh.
Requires Node 20+. Speaks both protocol eras on stdio: the 2026-07-28 revision (server/discover, per-request _meta envelope) and the initialize handshake every current client uses (2025-11-25 down to 2024-10-07), selected per connection.
Or connect remotely (no install)
Prefer not to install anything? mcpindex is also a hosted remote MCP server. Point any client that supports remote MCP (Claude connectors, Cursor, etc.) at:
code
https://mcpindex.ai/api/mcp
Streamable HTTP, no credentials. Same six tools as the npm package.
Claude Code
bash
claude mcp add --scope user mcpindex -- npx -y mcp-server-mcpindex@latest
Gemini CLI
bash
gemini mcp add -s user mcpindex npx -y mcp-server-mcpindex@latest
Use it from Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
@latest keeps you current: this is the advisory discovery server (not the in-path drift
gate), so it carries no version pin — npx fetches the newest on your next host restart, no
manual upgrade step.
Restart Claude Desktop. Then ask:
"Find me an MCP server that can read PDFs and write the contents to S3."
Claude calls recommend_mcp_for_task and returns the top 3 ranked servers with install commands.
check_tool_trust is the directory client integration surface (not the in-path mcpindex-gate). It lets agent frameworks (Composio, Mastra, LangChain, DSPy, raw LLM-tool-call loops) ask for an advisory screen verdict before dispatching a call. At v1 you will see REVIEW or UNVERIFIED — not a safety clearance.
Using Mastra? The sibling package @mcp-index/mastra ships this exact screen as a ready-made beforeToolCall hook - npm i @mcp-index/mastra, no wiring required.
Verdict contract (v1)
jsonc
{"directive":"ALLOW" | "DENY" | "REVIEW" | "UNVERIFIED","status":"EVALUATED" | "PARTIAL" | "STALE" | "ERROR","granularity":"description-level" | null,// scope of a PARTIAL screen"dimensions":[{"id":"tool_safety","verdict":"PASS","severity":"INFO"}],"expires_at":"2026-06-30T00:00:00Z","honest_limits":["conformance_monitored_not_enforced","calibrated_false_v1","advisory_deployment"],"verdict_contract_version":"1.0.0","server_id":"github","tool_name":"create_pull_request","source_url":"https://mcpindex.ai/api/v1/trust/tool/github/create_pull_request","fetched_at":"2026-05-28T18:42:11.118Z"}
The free-tier verdict ships directives + dimensions + freshness. Evidence quotes, LLM rationale, and chain history are paid-tier surfaces and intentionally omitted here.
Honest limits (pin these to your gate UI)
Every v1 verdict ships with these three caveats, and your gate SHOULD surface them on every dispatch decision:
conformance_monitored_not_enforced - publishers self-declare; mcpindex monitors drift but does not block at the network layer.
calibrated_false_v1 - dimension severities are not yet calibrated against real-world incident data.
advisory_deployment - the verdict is advisory; the agent (or human reviewing the agent) is the decision-maker.
History anchoring: OTS Bitcoin-anchored history; Bitcoin-finalized at N=6 confirmations (~1 hr); pending in ~10 min. Sub-window precision asserted, not proven.
Integration pattern (LangChain-style, direct LLM-tool-call convention)
js
import { Client } from'@modelcontextprotocol/sdk/client/index.js';
import { StdioClientTransport } from'@modelcontextprotocol/sdk/client/stdio.js';
const mcpindex = newClient({ name: 'gate', version: '1.0.0' }, { capabilities: {} });
await mcpindex.connect(newStdioClientTransport({
command: 'npx', args: ['-y', 'mcp-server-mcpindex@latest'],
}));
// gateToolCall wraps any agent tool dispatch. Plug it in front of// the LangChain / DSPy / Mastra / Composio tool-call hook.asyncfunctiongateToolCall({ serverId, toolName, invoke, askHuman }) {
const res = await mcpindex.callTool({
name: 'check_tool_trust',
arguments: { server_id: serverId, tool_name: toolName },
});
const verdict = JSON.parse(res.content[0].text);
// Pin the v1 caveats in the audit log no matter what.
audit.log({ verdict, caveats: verdict.honest_limits });
switch (verdict.directive) {
case'REVIEW':
// Fail-CLOSED to human. Do NOT auto-execute on REVIEW.// At v1 this is the common screened outcome (semantic-only).returnaskHuman({ verdict, action: `${serverId}/${toolName}` });
case'UNVERIFIED':
// No verdict on file (or upstream unreachable). Fail-CLOSED.// Recommend human review. Do NOT fail-open to invoke().returnaskHuman({
verdict,
action: `${serverId}/${toolName}`,
note: 'No trust verdict on file. Human review required before first use.',
});
case'ALLOW':
// Reserved in the contract — not produced by the v1 public screen.// Keep the branch for future conformance-earned ALLOW; do not expect it today.returninvoke();
case'DENY':
// Reserved in the contract — not produced by the v1 public screen.thrownewError(
`mcpindex denied ${serverId}/${toolName}: ${JSON.stringify(verdict.dimensions)}`,
);
default:
// Unknown directive. Fail-CLOSED.returnaskHuman({ verdict, action: `${serverId}/${toolName}` });
}
}
The load-bearing rule: never fail-open
If the verdict endpoint is unreachable, returns 404, times out, returns malformed JSON, or has no verdict on file yet for that server, check_tool_trust returns directive: "UNVERIFIED" + status: "ERROR". It never silently coerces to ALLOW. Your gate code SHOULD treat UNVERIFIED as "human review required", never as "looks fine, ship it."
status is telemetry about screen completeness, distinct from the directive trust decision: EVALUATED (full screen), PARTIAL (only part of the surface, e.g. description-level — see granularity), STALE (verdict past its freshness window), ERROR (unreachable / no verdict on file). A PARTIAL screen is never reported as EVALUATED.
This is tested. See test/trust.test.mjs.
Using the library directly (without MCP)
The trust client is also exported as a plain ES module:
js
import { checkToolTrust, assessServer } from'mcp-server-mcpindex/src/trust.mjs';
const verdict = awaitcheckToolTrust({
serverId: 'github',
toolName: 'create_pull_request',
});
if (verdict.directive !== 'ALLOW') {
// Hand to a human, log, or block.
}
Backend
By default, calls go to https://mcpindex.ai. Override with MCPINDEX_API_BASE=... if you self-host.
The free tier is rate-limited to 60 req/min/IP. Paid keys are coming for higher throughput and the full evidence-bearing verdict (evidence quotes, LLM rationale, chain history).
Related packages
Three ways to bring mcpindex into an agent, for different surfaces:
Package
Install
What it does
mcp-server-mcpindex(this package)
npm i -g mcp-server-mcpindex
Directory + advisory screen as an MCP server: find servers by task, and check_tool_trust before a call.
@mcp-index/mastra
npm i @mcp-index/mastra
The same advisory screen wired into Mastra as a beforeToolCall hook (warn / enforce).
@mcp-index/sdk
npm i @mcp-index/sdk
In-path drift gate: wrap() an MCP session and HOLD a call when a tool's contract drifts from your pin.
Advisory screen vs drift gate: this package and @mcp-index/mastra ask mcpindex "has this tool been vetted?" (a network verdict). @mcp-index/sdk asks a different question locally: "did this tool's contract change since I pinned it?" Complementary, and none depends on another.