MCP 서버

registry

com.policylayer/registry
MCP 및 에이전트 인프라 보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Checks MCP servers, stacks, and individual tools for identity, risk, authentication posture, and policy recommendations through a registry.

check_mcp_server
Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk grade, auth posture, freshness, and the tool surface listed riskiest-first. A server the registry does not know is queued for scanning by this very call — check back shortly.
입력 스키마
{'type': 'object', 'required': ['server'], 'properties': {'server': {'type': 'string', 'description': 'Registry slug, npm package name (e.g. @acme/mcp-server), remote URL, or server name.'}}}
check_mcp_stack
Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdict (attention signals and a suggested action) — and the lookup status for every miss; counts, grades and flagged tools come from the published records only. Costs one rate-limit unit per server.
입력 스키마
{'type': 'object', 'required': ['servers'], 'properties': {'servers': {'type': 'array', 'items': {'type': 'object', 'required': ['candidates'], 'properties': {'name': {'type': 'string', 'description': 'Your label for this server (e.g. its config key) — echoed back on the result.'}, 'candidates': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 5, 'description': 'Identifiers to try in order: npm package name, registry slug, or remote URL. Most package-like first.'}}}, 'maxItems': 25, 'description': 'One entry per server in the stack.'}}}
check_tool
One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. "should execute_sql on this server be permitted?"
입력 스키마
{'type': 'object', 'required': ['server', 'tool'], 'properties': {'tool': {'type': 'string', 'description': 'Tool name as the server declares it.'}, 'server': {'type': 'string', 'description': 'Registry slug or npm package name of the server.'}}}
get_change_events
The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at https://policylayer.com/registry/pricing.
입력 스키마
{'type': 'object', 'properties': {'limit': {'type': 'number', 'description': 'Max events (1-1000, default 200).'}, 'after_id': {'type': 'number', 'description': 'Return events with id greater than this cursor (default 0).'}, 'severity': {'enum': ['info', 'notice', 'warning', 'critical'], 'type': 'string', 'description': 'Minimum severity: that level and above.'}}}
search_registry
Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand) and tool count — follow up with check_mcp_server on the match you meant.
입력 스키마
{'type': 'object', 'required': ['query'], 'properties': {'limit': {'type': 'number', 'description': 'Max matches to return (1-20, default 10).'}, 'query': {'type': 'string', 'description': 'Substring to match against slug, name and packages.'}}}
추가됨
get_change_events
2026년 9월 17일 12:36 PM
추가됨
check_tool
2026년 9월 17일 12:36 PM
추가됨
search_registry
2026년 9월 17일 12:36 PM
추가됨
check_mcp_stack
2026년 9월 17일 12:36 PM
추가됨
check_mcp_server
2026년 9월 17일 12:36 PM