MCP Server

Dredd MCP

io.github.pduggusa/dredd-mcp
MCP & Agent Infrastructure Security Public & reachable MCP 2026-07-28

What this MCP does

Performs pre-flight security checks on MCP servers and their dependencies, returning a signed allow, advisory, review, or block verdict.

check_mcp_server
Pre-flight security verdict for an MCP server invocation. Judges BOTH server-level reputation AND the server's dependency graph (npm/pypi) against the DugganUSA threat-intel corpus (1.13M+ IOCs, Shai-Hulud + typosquat + LOLBin families). Returns BLOCK / ADVISORY / REVIEW / ALLOW with severity, evidence, dep-graph summary, and HMAC-signed response. REVIEW means we hold NO RECORD of this server -- not that it is safe. Treat REVIEW as do-not-proceed-blindly: a brand-new attacker-published server looks exactly like this. ALLOW is only returned when we actually resolved the server and scanned its dependency graph; check known_to_us and dep_graph.scanned to confirm. Use this BEFORE invoking any other MCP server tool, especially ones installed from outside the official MCP Registry.
Input schema
{'type': 'object', 'required': ['server'], 'properties': {'tool': {'type': 'string', 'description': 'Optional name of the specific tool being invoked'}, 'server': {'type': 'string', 'description': 'MCP server name (e.g. io.github.foo/bar) or substring'}, 'version': {'type': 'string', 'description': 'Optional version of the MCP server (semver)'}}, 'additionalProperties': False}
Added
check_mcp_server
Sept. 17, 2026, 12:45 p.m.