About this project

mcp-pin is an independent open-source project built and run by Gautam Khosla, a student. It is not affiliated with, endorsed by, or connected to Anthropic, the Model Context Protocol project, npm, GitHub, or any of the servers listed in the log.

What this site publishes

A record of the tool metadata that public MCP servers return when asked. Names, descriptions, input schemas, and annotations, along with a cryptographic hash of each and the date it was observed. All of it is information those servers publish openly to any client that connects.

Nothing here is a security assessment. A badge reading unchanged 91d means the fingerprint has not moved in 91 days. It does not mean a server is safe, well written, or trustworthy, and it should never be read that way.

How the crawler behaves

These are commitments, not aspirations. If the crawler ever violates one, that is a bug and I want to hear about it.

Opting out

If you maintain a server here and do not want it crawled, say so and it stops. Add it to OPTOUT.txt, open an issue titled opt out: your-server-name, or email me. No justification is requested and none is required. You will not be asked to explain yourself and I will not try to talk you out of it.

It takes effect on the next crawl and the pages come down. One thing stated honestly rather than glossed over: the log is append-only by design, so entries already written stay in the file. If you need existing entries removed as well, ask, and I will publish a signed note explaining what was removed and why, because silently editing a transparency log would defeat its entire purpose.

Corrections

If anything here is wrong about your server, tell me and I will fix it and say what changed. Accuracy matters more to this project than completeness.

No warranty

This is provided as is, without warranty of any kind, under the MIT licence. It is a hobby research project run by one person alongside university study. Do not treat it as a commercial service, do not build a compliance process on it, and do not assume it will still be running next year. The threat model is explicit about what the tool does not defend against.

Contact

Security issues: see SECURITY.md and use GitHub's private reporting rather than a public issue. Everything else: open an issue. For anything you would rather not discuss in public, my contact details are on my GitHub profile.