dev.tatastu

dev.tatastu/proof

VOUCH79·B

Stamp content with permanent, verifiable provenance. Hash locally, verify free forever.

Trust report

Scanned 2026-08-08 · MCP 2025-06-18

Scored by MCP Vouch against the OWASP MCP Top 10. SKIP applies to HTTP-only checks not relevant for stdio servers and is excluded from the score.

Is dev.tatastu/proof safe to use?

dev.tatastu/proof scores 79/100 — grade B, which is a solid posture with a few gaps worth reading. It passes 5 of the 9 OWASP MCP Top-10 checks that apply to it, with Insufficient Input Validation, Missing Authentication, Lack of Audit and Telemetry, and Supply Chain Risk returning a warning rather than a pass. 1 further check does not apply to this server's transport and is excluded from the score entirely — skipped is not the same as failed. This is what the scanner found on 2026-08-08, not a guarantee. Re-run it yourself with `npx mcpr scan`.

What a grade B means, the ten checks behind it, and the point maths are all on how we score MCP server trust.

Slug

mcpr-dev-tatastu-proof

License

Unspecified

Quality score

Not yet probed

Trust score

VOUCH79·B

Latest version

1.0.0

Published

2026-07-08

Homepage

tatastu.dev/proof

Repository

github.com/Tatastu-Labs/proof

Capabilities

Not yet declared in the manifest.

Embed the live badge

Always reflects the current grade. Score drops → badge drops. No vanity lock.

Live MCP Vouch trust badge for mcpr-dev-tatastu-proof
[![MCP trust score](https://mcpr.io/api/badge/mcpr-dev-tatastu-proof.svg)](https://mcpr.io/servers/mcpr-dev-tatastu-proof/)

Install

One-click cross-client install (Claude Code, Claude Desktop, Cursor, Windsurf) coming soon. The registry will write the correct config fragment to the correct file — no copy-paste.

Frequently asked questions

Is dev.tatastu/proof safe to use?
dev.tatastu/proof scores 79/100 — grade B, which is a solid posture with a few gaps worth reading. It passes 5 of the 9 OWASP MCP Top-10 checks that apply to it, with Insufficient Input Validation, Missing Authentication, Lack of Audit and Telemetry, and Supply Chain Risk returning a warning rather than a pass. 1 further check does not apply to this server's transport and is excluded from the score entirely — skipped is not the same as failed. This is what the scanner found on 2026-08-08, not a guarantee. Re-run it yourself with `npx mcpr scan`.
What is the dev.tatastu/proof trust score based on?
Ten checks derived from the OWASP MCP Top 10, run against the live server by the open-source MCP Vouch scanner. Applicable checks are summed and scaled to 0–100; checks that do not apply to the server's transport are skipped and leave the denominator entirely.
How do I install dev.tatastu/proof?
dev.tatastu/proof is installed like any other MCP server — add it to your client's MCP configuration. Cross-client one-click install is coming to MCP Registry; until then, the repository and homepage links on this page carry the maintainer's own instructions.