Pre-connect trust checks for AI agents and MCP servers using HVTracker's public trust registry.
Most developer tooling work still happens through a UI a human drives. HVTracker MCP MCP server moves it into the conversation instead. Pre-connect trust checks for AI agents and MCP servers using HVTracker's public trust registry.
MCP server for checking supply-chain trust before connecting to AI agents, frameworks, or MCP servers.
Because this one is hosted, setup is mostly authentication — you point your client at the endpoint and approve access. Nothing runs on your machine, so there is no runtime to keep patched.
The server publishes 4 tools. What each one is for:
verify_mcp_server — pre-connect trust verdict for an MCP server, package, GitHub repo, or agent namecheck_agent_trust — trust profile for a tracked AI agent or framework — incl. runtime capabilities (MCP status, providers, plugin surface, provenance drift) and the URLcompare_agents — two agents side by side with an evidence-based verdict and the published compare-page linksearch_agents — search the HVTracker registry by name, repo, description, or categoryConfiguration is passed through the environment: HVTRACKER_BASE_URL. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. HVTracker MCP's toolset — verify_mcp_server, check_agent_trust, compare_agents and 1 more — is a fair guide to whether it matches your workflow. It is maintained by YugantM; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against HVTracker MCP's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| verify_mcp_server | pre-connect trust verdict for an MCP server, package, GitHub repo, or agent name. |
| check_agent_trust | trust profile for a tracked AI agent or framework — incl. runtime capabilities (MCP status, providers, plugin surface, provenance drift) and the URL of its Ed25519-signed trust credential. |
| compare_agents | two agents side by side with an evidence-based verdict and the published compare-page link. |
| search_agents | search the HVTracker registry by name, repo, description, or category. |
{
"mcpServers": {
"hvtracker": {
"url": "https://hvtracker.net/mcp"
}
}
}Configuration as documented by the project. Restart the client after saving.
| Variable | Description | Required |
|---|---|---|
| HVTRACKER_BASE_URL | Endpoint or connection string the server talks to. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.