polygraphso
v0.4.1
Published
Look up the polygraph for an MCP server. Independent, lab-evaluated trust grades — see polygraph.so.
Maintainers
Readme
polygraphso
Look up the polygraph for an MCP server.
Polygraph publishes independent, lab-evaluated trust grades for AI agents and MCP servers. This CLI is a thin wrapper around the public lookup endpoint — a sub-second check against precomputed grades.
The npm package is polygraphso (the polygraph name was taken); the brand and product noun are still "polygraph".
Install
npx polygraphso check npm/@modelcontextprotocol/server-filesystemOr install globally:
npm i -g polygraphso
polygraphso check pypi/mcp-server-gitUsage
polygraphso check <registry>/<owner>/<name>
polygraphso request <registry>/<owner>/<name>
polygraphso list [--json]
polygraphso --version
polygraphso --helpRegistry-prefixed refs are required. redis exists on npm, pypi, and GitHub with different content — the prefix says which one you mean.
Examples:
polygraphso check npm/@modelcontextprotocol/server-filesystem
polygraphso check npm/lodash
polygraphso check pypi/mcp-server-git
polygraphso check github/anthropic/mcp-server-fooOutput
Graded server:
→ polygraph: A · version 2.1.0 · litmus-v11 · 2026-06-24
→ evidence → polygraph.so/mcp/npm/@modelcontextprotocol/server-filesystemThe line carries the grade (A–F), the exact graded version, the methodology version, and the date. If the version you'd actually run differs from the graded one, the check reports the grade for the version in play and notes the gap:
→ polygraph: A · version 2.1.0 · litmus-v11 · 2026-06-24
→ note: graded 2.1.0; your version is 2.2.0 (not yet graded)
→ evidence → polygraph.so/mcp/npm/@modelcontextprotocol/server-filesystemUntracked / not-yet-graded server — with the actions you can take:
→ not available yet
→ request a grade → polygraphso request npm/obscure-mcp-server
→ grade it now → npx -y -p @polygraphso/litmus polygraphso-litmus litmus npm/obscure-mcp-server
→ notify me → polygraph.so/notify?for=npm/obscure-mcp-serverGrades are read from the hosted runner's published results — this CLI never grades, it's a
sub-second lookup. To grade a server yourself, run the open harness (@polygraphso/litmus).
Request a grade
If check comes back "not available yet", add the server to polygraph's public grading queue:
polygraphso request npm/@some/ungraded-serverFree and best-effort — polygraph runs the litmus test and publishes the grade, which you then
read with polygraphso check. It doesn't return a grade synchronously.
Browse the tracked set
polygraphso listPrints every graded MCP server as server_ref | grade, sorted by grade (A→F, then ref). Pipe through jq with --json:
polygraphso list --json | jq '.servers[] | select(.polygraph == "A")'Configuration
Override the API endpoint (useful for testing):
POLYGRAPH_API_URL=http://localhost:3000 polygraphso check npm/lodashLinks
- Site: https://polygraph.so
- Source: https://github.com/polygraphso/core
- Issues: https://github.com/polygraphso/core/issues
