
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
polygraphso
Advanced tools
Look up the polygraph for an MCP server. Independent, lab-evaluated trust grades — see polygraph.so.
Look up the polygraph for an MCP server.
Polygraph publishes independent, lab-evaluated trust grades for AI agents and MCP servers. This CLI is a thin wrapper around the public lookup endpoint — a sub-second check against precomputed grades.
The npm package is polygraphso (the polygraph name was taken); the brand and product noun are still "polygraph".
npx polygraphso check npm/@modelcontextprotocol/server-filesystem
Or install globally:
npm i -g polygraphso
polygraphso check pypi/mcp-server-git
polygraphso check <registry>/<owner>/<name>
polygraphso request <registry>/<owner>/<name>
polygraphso list [--json]
polygraphso --version
polygraphso --help
Registry-prefixed refs are required. redis exists on npm, pypi, and GitHub with different content — the prefix says which one you mean.
Examples:
polygraphso check npm/@modelcontextprotocol/server-filesystem
polygraphso check npm/lodash
polygraphso check pypi/mcp-server-git
polygraphso check github/anthropic/mcp-server-foo
Graded server:
→ polygraph: A · version 2.1.0 · litmus-v11 · 2026-06-24
→ evidence → polygraph.so/mcp/npm/@modelcontextprotocol/server-filesystem
The line carries the grade (A–F), the exact graded version, the methodology version, and the date. If the version you'd actually run differs from the graded one, the check reports the grade for the version in play and notes the gap:
→ polygraph: A · version 2.1.0 · litmus-v11 · 2026-06-24
→ note: graded 2.1.0; your version is 2.2.0 (not yet graded)
→ evidence → polygraph.so/mcp/npm/@modelcontextprotocol/server-filesystem
Untracked / not-yet-graded server — with the actions you can take:
→ not available yet
→ request a grade → polygraphso request npm/obscure-mcp-server
→ grade it now → npx -y -p @polygraphso/litmus polygraphso-litmus litmus npm/obscure-mcp-server
→ notify me → polygraph.so/notify?for=npm/obscure-mcp-server
Grades are read from the hosted runner's published results — this CLI never grades, it's a
sub-second lookup. To grade a server yourself, run the open harness (@polygraphso/litmus).
If check comes back "not available yet", add the server to polygraph's public grading queue:
polygraphso request npm/@some/ungraded-server
Free and best-effort — polygraph runs the litmus test and publishes the grade, which you then
read with polygraphso check. It doesn't return a grade synchronously.
polygraphso list
Prints every graded MCP server as server_ref | grade, sorted by grade (A→F, then ref). Pipe through jq with --json:
polygraphso list --json | jq '.servers[] | select(.polygraph == "A")'
Override the API endpoint (useful for testing):
POLYGRAPH_API_URL=http://localhost:3000 polygraphso check npm/lodash
FAQs
Look up the polygraph for an MCP server. Independent, lab-evaluated trust grades — see polygraph.so.
We found that polygraphso demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.