mcpbeat Sign in

MCP Server Attestation

local only

MCP Server Attestation runs on your own machine — the client starts it, so there is no endpoint to ping. 38 installs a week from npm. Last commit 13 Sep 2026.

Ed25519-signed MCP tool manifests + spawn attestation. Layer-2 supply-chain hardening.

Installs per day peak 21 · avg 7 · -6% w/w
a month agotoday
38
Installs / week
npm · mcp-attest-demo
0
Stars
0 open issues
13 Sep 2026
Last commit
0 releases in 90 days
MIT
License
TypeScript

What the code does

We read the source, 19 h ago · rules 3dff92dd89df

A tool parameter reaches a dangerous call

A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.

A tool parameter reaches a file or shell call attest_sign_manifest.manifestPath → packages/demo-server/src/tools/index.ts:181, attest_verify_manifest.manifestPath → packages/demo-server/src/tools/index.ts:57, attest_verify_manifest.manifestPath → packages/demo-server/src/tools/index.ts:177 и ещё 2
    await fs.writeFile(resolve(input.outputPath), JSON.stringify(signed, null, 2) + "\n");

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

A tool parameter here reaches a dangerous call

That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add server-attestation -- npx -y mcp-attest-demo
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "server-attestation": {
      "args": [
        "-y",
        "mcp-attest-demo"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.server-attestation]
command = "npx"
args = ["-y", "mcp-attest-demo"]
.cursor/mcp.json
{
  "mcpServers": {
    "server-attestation": {
      "args": [
        "-y",
        "mcp-attest-demo"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "server-attestation": {
      "args": [
        "-y",
        "mcp-attest-demo"
      ],
      "command": "npx"
    }
  }
}

Alternatives to MCP Server Attestation

same job, measured the same way
Paceproof
by rudrendupaul

Verifies Ed25519-signed attestation records and builds audit reports via MCP tools.

32 installs/wk local only
Firmware Attestation MCP
by csoai-org

Firmware Attestation MCP — hardware trust layer for sovereign AI. Scan firmware, check

142 installs/wk local only
Trust Chain MCP
by csoai-org

Trust Chain MCP server. Tools: create trust anchor, verify chain, add attestation. Built by MEOK AI

177 installs/wk local only
AIShield Security Scanner
by lm203688

Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

46 installs/wk 9 tools local only
Bostrom MCP
by cyberia-to

86-tool MCP server for Bostrom blockchain: read chain state and sign transactions

40 installs/wk local only
Supply Chain Logistics MCP
by thenextgennexus

MCP server giving AI agents one-connection access to supply-chain & logistics data: AIS vessel track

answering
Stablecoin reserve attestations
by agentwares

Stablecoin reserve attestations as JSON: reserves, composition, attestor, on-chain supply, ratio.

209 installs/wk 2 tools answering
Signet MCP Tools
by prismer-ai

MCP server exposing Signet cryptographic signing, verification, and content hash tools over stdio.

52 installs/wk local only

MCP Server Attestation — questions

Answers built from our own checks of this server.

Why is there no uptime for MCP Server Attestation?
MCP Server Attestation runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package mcp-attest-demo was installed 38 times last week.
How do I connect MCP Server Attestation?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls mcp-attest-demo straight from npm; nothing to host, nothing to sign up for.
How many people use MCP Server Attestation?
The npm package mcp-attest-demo was installed 38 times in the last week. Week over week that is -6%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is MCP Server Attestation open source?
Yes — it is published under the MIT licence, written in TypeScript and 0 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.