RedHub AIRedHub AI
Tool Gate · How it works

How the gate works

How the MCP Server & Skill Trust gate works

This tool grades a third-party MCP server or agent skill before you install it. Each signal is scored 0–1; the verdict is the weakest one — then a gate that can only make it worse.

The 6 signals

01Publisher provenance & verification
02Version & change-history review
03Declared scope matches actual scope
04Credential handling (no plaintext secrets)top trigger
05Update & approval behavior (no silent auto-approve)top trigger
06Sandbox / egress containment
TRUSTED
every signal reads Trusted (2)
REVIEW
weakest signal is Review (1)
DO NOT INSTALL
any signal is Fail (0) - or credential handling and approval behavior both read below Trusted
Supply-chain gate · worsen-only

If both credential handling and approval behavior score below full (Review or Fail), the verdict forces to DO NOT INSTALL even if the weakest signal alone would only read REVIEW.

DO NOT INSTALL

Why: Credential handling and approval behavior are both Review, not Fail - but with neither fully in place, a malicious update could reach your secrets with no explicit approval, so the gate forces DO NOT INSTALL even though the weakest signal alone would only read REVIEW. weakest signal 1/1 · 3 of 6 signals Trusted.

Fix firstCredential handling

A clean sheet didn’t save it. The verdict is the weakest signal — and a top trigger is dispositive on its own — so it names the one thing to fix first. Grades the artifact from your own marks, never people. Not a code scanner, malware detector, or security audit - a decision aid, not a guarantee a server is safe.