
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
Know if you can trust your MCP server. Execution verification + trust judgment for AI agents.
Know if you can trust your MCP server.
Agents call tools. Some fail silently. Veridict gives you a signal.
Part of the emerging Agent Trust Stack (Runtime Verification Layer).
npm install veridict
import { withVeridict } from "veridict"; // 1. import
// ... register your tools as usual ...
withVeridict(server, { name: "my-server" }); // 2. wrap
await server.connect(transport);
Done. Every tool call is now logged. Two new tools are automatically added:
veridict_stats — execution statisticsveridict_can_i_trust — trust judgment (YES / CAUTION / NO)can_I_trust("my-server")?
verdict: "yes"
confidence: 0.99
success_rate: 0.992
total_executions: 1247
reason: "success_rate 99.2% over 1247 executions"
See executions in real-time:
withVeridict(server, { name: "my-server", verbose: true });
Output (stderr):
[veridict] monitoring "my-server"
[veridict] search_docs ok 120ms
[veridict] create_item ok 85ms
[veridict] fetch_data FAIL 3201ms — timeout
[veridict] search_docs ok 94ms
npx veridict # Show all tracked servers
npx veridict stats my-server # Detailed stats
npx veridict trust my-server # Trust judgment
| Success Rate | Verdict | Meaning |
|---|---|---|
| >= 95% | yes | Trustworthy |
| >= 80% | caution | Some failures detected |
| < 80% | no | High failure rate |
| < 10 executions | unknown | Insufficient data |
withVeridict(server, {
name: "my-server", // Required: server identifier
instanceId: "prod-1", // Optional: distinguish instances
dbPath: "./my-logs.db", // Optional: custom DB path (default: ~/.veridict/executions.db)
minExecutions: 20, // Optional: min data for judgment (default: 10)
verbose: true, // Optional: log to stderr (default: false)
});
Combine static analysis with runtime monitoring for full-stack trust:
# Step 1: Static scan with MCP Trust Kit (v0.5.0+)
npx mcp-trust-kit scan --json-out layer1-baseline.json --cmd node my-server.js
import { withVeridict, parseLayer1Report } from "veridict";
import report from "./layer1-baseline.json";
withVeridict(server, {
name: "my-server",
baseline: parseLayer1Report(report), // Layer 1 → Layer 2
});
What this does:
dangerous_fs_write) are factored into trust judgmentscan_timestamp is preserved for Layer 3 temporal decay logicbaseline.raw for cross-org consumersPart of the Agent Trust Stack:
Layer 1: MCP Trust Kit (pre-deploy) → "Is this server safe to run?"
Layer 2: Veridict (runtime) → "Is this server actually reliable?"
Layer 3: SATP/XAIP (cross-org) → "Should I trust this across boundaries?"
~/.veridict/executions.db)If you're building MCP servers or agents, I'd love your feedback. Try Veridict and tell me what breaks.
MIT
FAQs
Know if you can trust your MCP server. Execution verification + trust judgment for AI agents.
The npm package veridict receives a total of 16 weekly downloads. As such, veridict popularity was classified as not popular.
We found that veridict demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.