Metadata-Version: 2.5
Name: attestari-mcp
Version: 0.1.0
Summary: Attestari's verdict on an npm or PyPI package version, over MCP: the lookup API's answer, asked before a package is installed.
Project-URL: Homepage, https://attestari.ai
Project-URL: Documentation, https://attestari.ai/pricing#line-2
Author: Attestari
License-Expression: MIT
License-File: LICENSE
Keywords: attestari,mcp,model-context-protocol,security,supply-chain
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Security
Requires-Python: >=3.12
Requires-Dist: httpx2>=2.13
Requires-Dist: mcp<3,>=2.3
Requires-Dist: pydantic>=2.9
Requires-Dist: starlette>=0.40
Requires-Dist: uvicorn>=0.30
Description-Content-Type: text/markdown

# attestari-mcp

<!-- mcp-name: ai.attestari/attestari -->

Attestari's verdict on an npm or PyPI package version, over the Model Context Protocol. The answer is the Attestari
lookup API's: the grade, the decision, the confirmed findings by reason code and place, and the methodology version
and document hash the decision cites. "Not examined" is its own answer and is never a sign that a package is safe.

Every lookup needs an Attestari API key (the Developer tier and above, https://attestari.ai/pricing#line-2) and is
counted as one lookup, as through the API. What is sent is the ecosystem, the package name and the version, and
nothing else.

## Run it locally

```
ATTESTARI_API_KEY=att_live_... uvx attestari-mcp
```

It speaks MCP over standard input and output and opens no port. In an MCP client's configuration:

```json
{
  "mcpServers": {
    "attestari": {
      "command": "uvx",
      "args": ["attestari-mcp"],
      "env": { "ATTESTARI_API_KEY": "att_live_..." }
    }
  }
}
```

`ATTESTARI_API_URL` changes the lookup API's address (default `https://api.attestari.ai`).

## Tools

- `lookup_package`: one package (`ecosystem`: `npm` or `pypi`; `name`; `version`, or none for the latest version
  examined).
- `lookup_packages`: up to 20 packages at once, each counted as one lookup.

Both only read. Each answer says its outcome: `graded`, `not_gradeable` (examined, no opinion given), `not_a_server`
(out of scope), `not_examined`, `under_re_examination`, `refused` (the key, the plan or a limit) or `unavailable`.

## What the answer carries from a package

Its name, its version, and the file paths of its findings and capabilities with their line numbers. No excerpt of a
package's code or text is passed on: text written by a package's publisher never reaches the agent through this
server.

## Licence

MIT.
