Back to Browse

Hlido MCP Server

Developer ToolsModerate6.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Independent AI-agent reviews: trust checks, evidence scorecards, incident registry, recommendations.

About

Independent AI-agent reviews: trust checks, evidence scorecards, incident registry, recommendations.

Remote endpoints: streamable-http: https://hlido.eu/mcp

Security Report

6.8
Moderate6.8Moderate Risk

A well-structured MCP server for querying Hlido's public AI-agent review registry. Authentication is intentionally absent (public data only), permissions are appropriate for a read-heavy data adapter, and the code follows secure patterns for handling credentials and external data. Minor findings relate to code quality and telemetry edge cases rather than security vulnerabilities. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Hlido MCP Server

smithery badge

Independent trust scores, claim audits, and comparisons for AI agents — queryable by your agent over MCP.

Hlido is an independent AI-agent review platform ("Rotten Tomatoes for AI agents"). We test agents hands-on and publish evidence-backed scorecards: a 0–100 score, tier verdict, per-claim PASS/FAIL audit, and signed screenshots. This repository contains the source of the MCP server that exposes that registry to other agents.

Use the hosted server (no install)

The server runs as a Cloudflare Worker at:

https://hlido.eu/mcp

Claude Code:

claude mcp add --transport http hlido https://hlido.eu/mcp

Claude Desktop / Cursor / any MCP client (mcpServers config):

{
  "mcpServers": {
    "hlido": { "url": "https://hlido.eu/mcp" }
  }
}

Also listed on Smithery and mcp.so.

Tools

ToolWhat it answers
trust_check"Is agent X trustworthy?" — score, tier, verdict for a slug
find_trusted"Find me a trusted agent for " — filtered registry search
verify_claim"Does X really do Y?" — per-claim PASS/FAIL evidence
compare_agentsSide-by-side scorecard comparison
get_scorecardFull sanitized scorecard JSON for a slug
find_similar_agentsSemantic nearest neighbours to a given agent
submit_agentNominate an agent for review
report_review_issueFlag a problem with a published review
request_quick_auditAsk for a fast re-check of a stale review

(plus discovery/metadata tools — see src/index.mjs for the live tool table)

Design principles

  • Public data only. The server reads the same JSON published at hlido.eu/data/* (registry, scorecards, attestations). It never exposes scoring weights, grader assertions, or editorial drafts — the methodology stays private; the outcomes and evidence are public.
  • No auth, no tracking. Anonymous JSON-RPC. Lightweight daily per-tool counters are the only telemetry.
  • Thin by intent. This is an adapter over open data. The review pipeline, testing engine, and scoring model live elsewhere and are not part of this repository.

Self-hosting

It's a standard Cloudflare Worker. Copy wrangler.toml.example to wrangler.toml, set your account id, and npx wrangler deploy. Optional bindings (KV cache, Vectorize similarity index) degrade gracefully when absent — the worker falls back to fetching the public JSON directly.

Data & licensing

Links

Run with Docker

docker build -t hlido-mcp .
docker run -p 8080:8080 hlido-mcp

The container runs the worker on the local workerd runtime via wrangler dev — no Cloudflare account needed. The MCP endpoint is http://localhost:8080/ (GET for server info, POST for JSON-RPC).

Reviews

No reviews yet

Be the first to review this server!