Back to Browse

Mcpqueen MCP Server

Developer ToolsModerate6.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

The evidence layer for MCP: live operational grades plus Trust Receipts for every registry server.

About

The evidence layer for MCP: live operational grades plus Trust Receipts for every registry server.

Remote endpoints: streamable-http: https://mcpqueen.com/mcp

Security Report

6.2
Moderate6.2Moderate Risk

mcpqueen is a well-intentioned MCP registry auditor with solid architecture and permissioning that matches its grading purpose. However, there are several code quality and input validation gaps that merit attention: unvalidated database writes from registry sync, missing CSRF protection on feedback submissions, insufficient logging of probe operations, and some edge cases in identifier resolution. No malicious patterns or critical vulnerabilities detected, but these issues should be addressed before production at scale. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

MCP Queen

MCP Queen is a public discovery and evidence service for Model Context Protocol servers. It publishes dated operational observations, tool metadata, and separate Trust Receipts so developers and agents can inspect evidence before deciding what to connect.

An MCP Queen operational grade is not a security, privacy, data-quality, or compliance certification. Missing evidence is unaudited, not safe.

Use the hosted endpoint

The public Streamable HTTP endpoint requires no account for rate-limited evaluation:

https://mcpqueen.com/mcp

It exposes six read-only discovery/evidence tools and one additive feedback tool:

  • search_servers
  • search_tools
  • list_grades
  • get_server_grade
  • get_trust_receipt
  • search_trust_evidence
  • submit_feedback — writes only to a quarantined review queue

For human-readable setup and current service limits, use mcpqueen.com/connect.

Claude Code

claude mcp add --transport http mcpqueen https://mcpqueen.com/mcp

Direct protocol examples

The model-free examples under examples/clients call the hosted endpoint directly:

node examples/clients/node-http.mjs "GitHub issue triage"

The Python version uses the official MCP SDK. Additional examples show bounded integration with LangChain, LlamaIndex, Cloudflare Agents, Hugging Face, and the OpenAI Responses API. Agent examples allowlist only the six read-only tools; submit_feedback is excluded from automatic model access.

Optional local stdio bridge

This repository contains a small zero-dependency stdio bridge for clients that cannot connect to a remote Streamable HTTP endpoint directly. The bridge does not contain MCP Queen's hosted implementation or evidence corpus; it forwards JSON-RPC messages to https://mcpqueen.com/mcp.

git clone https://github.com/mcpqueen/mcpqueen.git
cd mcpqueen
npm ci
npm start

To point the bridge at another compatible endpoint during local testing, set MCPQUEEN_MCP_URL in the process environment.

Docker is also supported:

docker build -t mcpqueen-bridge .
docker run --rm -i mcpqueen-bridge

What this public repository contains

The production Worker, deployment configuration, evidence database, submission packages, operational records, and private source history are not part of this public developer surface. This repository is not a production deployment source.

Verify locally

npm ci
npm test

The tests exercise the bridge against a local mock endpoint and verify that public documentation and package scripts reference files that are actually in this repository.

License and support

Code in this repository is available under the MIT License. Product documentation, privacy, terms, and support are available from mcpqueen.com.

Reviews

No reviews yet

Be the first to review this server!