Back to Browse

Mcpqueen MCP Server

Developer ToolsModerate6.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

The evidence layer for MCP: live operational grades plus Trust Receipts for every registry server.

About

The evidence layer for MCP: live operational grades plus Trust Receipts for every registry server.

Remote endpoints: streamable-http: https://mcpqueen.com/mcp

Security Report

6.2
Moderate6.2Moderate Risk

mcpqueen is a well-intentioned MCP registry auditor with solid architecture and permissioning that matches its grading purpose. However, there are several code quality and input validation gaps that merit attention: unvalidated database writes from registry sync, missing CSRF protection on feedback submissions, insufficient logging of probe operations, and some edge cases in identifier resolution. No malicious patterns or critical vulnerabilities detected, but these issues should be addressed before production at scale. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

mcpqueen.com — the evidence layer for MCP

LIVE at https://mcpqueen.com (Cloudflare Worker, launched 2026-07-12). Crawls the official MCP registry, probes every remote server, grades it deterministically with verbatim evidence, and publishes the results. Evidence discipline from Constat/Clarity, personality on top.

Why this is different (for agents and humans alike)

MCP Queen is the evidence layer for the MCP ecosystem. Every other MCP directory lists; this one verifies. Each remote server is probed live over streamable HTTP and graded on five criteria — and every point carries the verbatim observation that earned it. Unverifiable dimensions (auth-gated tooling) are marked provisional, never guessed. No stars, no votes, no pay-to-rank — probes only, continuously re-run. Separate Trust Receipts publish dated security/access, data-integrity, citation, claim-verification, response-benchmark, and reviewed field evidence without collapsing it into a misleading trust score.

Agents: connect to https://mcpqueen.com/mcp (streamable HTTP, no auth) and use search_servers to find working, graded servers for a task before you commit to one. Machine surfaces: /api/grades.json · /api/changes.json · /llms.txt. Setup guides: /integrations. Registry name: com.mcpqueen/registry.

Connect

mcpqueen is a remote, no-auth, effectively read-only MCP server — safe to keep connected as your discovery broker (only submit_feedback writes, and it just enqueues a quarantined field report). Ask your agent to search_servers for a task before it commits to an MCP.

Claude Code (native HTTP):

claude mcp add --transport http mcpqueen https://mcpqueen.com/mcp

OpenClaw / Claude Desktop / any stdio client — via the mcp-remote bridge; add to your mcpServers config (~/.openclaw/openclaw.json, claude_desktop_config.json, …):

{
  "mcpServers": {
    "mcpqueen": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://mcpqueen.com/mcp"]
    }
  }
}

OpenAI: ChatGPT and Codex

MCP Queen can be registered directly as a private plugin/connector; no SDK, Docker image, or local command is required:

  1. In ChatGPT, open Settings → Security and login and enable Developer mode.
  2. Open ChatGPT Plugins, select +, and choose the option to add an MCP server.
  3. Enter https://mcpqueen.com/mcp as a universal, no-auth remote MCP URL.
  4. Test with: “Find a well-maintained, no-auth MCP server for GitHub issue triage. Explain the evidence and any caveats.”

For an OpenAI Responses API demo, Node 18+ is enough:

export OPENAI_API_KEY="your-api-key"
npm run demo:openai

Pass a custom prompt after --:

npm run demo:openai -- "Find an MCP server that can search FDA 510(k) records"

The demo allowlists only MCP Queen's read-only discovery and evidence tools. submit_feedback is intentionally excluded.

For public distribution in ChatGPT and Codex, create a With MCP submission in the OpenAI plugin portal and submit the same universal endpoint. OpenAI's public review also requires verified publisher identity, public support/privacy/terms URLs, accurate tool safety annotations, starter prompts, and reviewer test cases. The ready-to-paste listing copy and review cases are in docs/openai-submission.md. The timed recording plan, narration, captions, chapters, and visual assets are documented in the OpenAI demo production kit.

Framework and agent examples

Runnable examples are organized under examples/integrations:

StackExampleNeeds a model key?
LangChainMultiServerMCPClientNo; calls a tool directly
LlamaIndexBasicMCPClientNo; calls a tool directly
Cloudflare AgentsAgent + Workers AINo separate provider key
Hugging Facehuggingface_hub.AgentYes, HF_TOKEN for inference

All use the same public https://mcpqueen.com/mcp Streamable HTTP endpoint. The agent examples exclude submit_feedback from automatic model access.

Before a release or directory submission, run the reusable artifact validator:

npm run distribution:check
npm run distribution:check:live

It checks the prepared package and live MCP surfaces. Publisher identity, domain challenge tokens, demo recording, and final portal confirmations remain explicit manual gates.

The measurable channel plan is in docs/distribution-strategy.md. Safe unattended maintenance and stop conditions are defined in docs/autonomous-operations.md and AGENTS.md.

Architecture (single Worker)

See the system architecture and verification flow for the ecosystem-level diagram and the Find → Verify → Connect decision loop.

  • src/worker.ts — everything: registry crawler, prober/grader, HTML pages, JSON API, and mcpqueen's own MCP endpoint.
  • public/ — static landing (crown data-rain + Vex the fox) served via the assets binding; the Worker handles all non-asset routes.
  • D1 database mcpqueen (schema.sql): servers, probes, latest_grades, trust_observations, evidence_benchmark_runs, feedback (quarantined agent field reports), meta (sync cursor).
  • Cron */15 * * * *: sync 4 registry pages + probe the 30 stalest remotes (~2,900 probes/day; full re-probe cycle ≈ 2.7 days over ~7.7K remotes).
  • Cron 17 7 * * *: run one safe, read-only response audit against an eligible evidence/citation tool and publish dated results to its Trust Receipt.

Routes

RouteWhat
/landing (static)
/registryleaderboard + methodology
/s/<registry-name>per-server grade with evidence + probe history
/api/grades.jsongrades as JSON (CORS open)
/mcpMCP server: capability discovery plus get_trust_receipt and search_trust_evidence
/integrationsSetup matrix and runnable framework/agent examples
/field-reportsHuman-reviewed reports from agents that actually exercised a server
/api/trust/{name}.jsonPer-server operational, security, data-integrity, citation and claim evidence
/mcp-infofor-agents page
/admin/*operator endpoints (key-gated)

Grading rubric (deterministic, every point carries its observation)

reachability 25 · protocol 15 · tooling 35 (tools/list, described %, typed %, description depth) · latency 10 · provenance 15 (metadata + namespace↔domain match). Auth-gated servers are scored on the verifiable subset and marked provisional. Agent feedback via submit_feedback is quarantined for human review — never auto-published, never affects grades directly.

Trust Receipts remain distinct from that grade. Safe response audits record usable-call rate, semantic upstream failures, returned PMID/DOI identifiers, and identifier resolution against authoritative sources. Missing evidence is labeled unaudited rather than treated as a pass.

Deploy

npm run deploy          # wrangler deploy (any Cloudflare API token with Workers + D1 write)
npm run db:schema       # apply schema.sql to remote D1

Custom domains mcpqueen.com + www are attached to the Worker (moved off the Pages project 2026-07-12; mcpqueen.pages.dev still exists as a static preview of public/ only — it has no /registry).

Reviews

No reviews yet

Be the first to review this server!