AnchorRegistry MCP server
SaferSkills independently audited Ar Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The AnchorRegistry MCP server. Resolve any AR-ID, manifest hash, or provenance tree from any MCP-compatible AI client.
Endpoint: https://mcp.anchorregistry.ai/mcp
Settings → Integrations → Add server. URL: https://mcp.anchorregistry.ai/mcp
claude mcp add --transport http anchorregistry https://mcp.anchorregistry.ai/mcpSettings → MCP → Add new MCP server. Name: anchorregistry · Type: http · URL: https://mcp.anchorregistry.ai/mcp
ar_verify_aridResolves an AR-ID to its full provenance record.
"What's at AR-2026-qnPOJ1z?"
ar_verify_by_hashResolves an artifact by SHA-256 manifest hash.
ar_resolve_treeReturns the full provenance tree for any AR-ID.
ar-mcp is a thin proxy. Every tool call hits api.anchorregistry.ai and returns the JSON unchanged. No data is logged, no credentials are stored, no state is held between requests.
The full surface is documented at:
v0.2 will add ar_check_balance and ar_register_artifact once the MCP credential-handling pattern stabilizes across clients. ar_seal_tree is deferred indefinitely (irreversible action; needs robust user-confirmation primitives the protocol does not yet provide). The deferred tools are fully implemented and live in src/future-tools.ts — enabling them is a one-line flip per tool.
npm install
npm test # vitest, hits live api.anchorregistry.ai
npm run type-check
npm run dev # wrangler dev — http://localhost:8787
npm run deploy # wrangler deployVerify locally with the MCP inspector:
npx @modelcontextprotocol/inspector http://localhost:8787/mcpMIT.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.