Tool Gate · How it works
How the MCP Server & Skill Trust Gate gate works
How the MCP Server & Skill Trust Gate scores 6 supply-chain trust signals by the weakest: a credentials-and-approval gate forces DO NOT INSTALL when both are only partial — which is how a server scoring 75/100 on context still reads DO NOT INSTALL.
How the gate works
This tool grades a third-party MCP server or agent skill before you install it. Each of 6 signals is scored 0–1 from your own evidence; the verdict is the weakest one — and then it is run past a gate that can only make the verdict worse.
The 6 signals
| Signal | Role |
|---|---|
| Publisher provenance & verification | signal |
| Version & change-history review | signal |
| Declared scope matches actual scope | signal |
| Credential handling (no plaintext secrets) | top trigger |
| Update & approval behavior (no silent auto-approve) | top trigger |
| Sandbox / egress containment | signal |
The verdict bands
If both credential handling and approval behavior score below full (Review or Fail), the verdict forces to DO NOT INSTALL even if the weakest signal alone would only read REVIEW.
In the worked sample 3 of 6 signals Trusted (weakest 1) and it still reads DO NOT INSTALL — Credential handling and approval behavior are both Review, not Fail - but with neither fully in place, a malicious update could reach your secrets with no explicit approval, so the gate forces DO NOT INSTALL even though the weakest signal alone would only read REVIEW. The one thing to fix first: Credential handling.
Common questions
Can a profile look clean on the How the MCP Server & Skill Trust gate works and still fail?
Yes. The verdict is the weakest of 6 signals, then run past a worsen-only gate — the Supply-chain gate — that can only make it worse. In the worked sample 3 of 6 signals Trusted (weakest 1) and it still reads DO NOT INSTALL, because credential handling and approval behavior are both Review, not Fail - but with neither fully in place, a malicious update could reach your secrets with no explicit approval, so the gate forces DO NOT INSTALL even though the weakest signal alone would only read REVIEW.
What is a worsen-only gate?
A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-clean sheet, because a single disqualifying gap shouldn't hide behind everything that passed. The tool also names the one thing to fix first — here, "Credential handling".
Grades the artifact from your own marks, never people. Not a code scanner, malware detector, or security audit - a decision aid, not a guarantee a server is safe.
Embed this diagram
Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.
Interactive — renders the live diagram
<iframe src="https://redhub.ai/visuals/tool/mcp-server-skill-trust-gate.html" title="How the MCP Server & Skill Trust Gate gate works — RedHub AI" width="760" height="1647" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/mcp-server-skill-trust-gate">How the MCP Server & Skill Trust Gate gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>Image + link — a static picture for any blog
<a href="https://redhub.ai/visuals/tool/mcp-server-skill-trust-gate"><img src="https://redhub.ai/visuals/tool/mcp-server-skill-trust-gate-share.png" alt="Diagram of the MCP Server & Skill Trust Gate: six supply-chain trust signals scored by the weakest and a credential/approval gate forcing DO NOT INSTALL at a 75/100 context score." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>This is how MCP Server & Skill Trust Gate works. More diagrams in the Visual Field Guide.