Attestari
Attestari's verdict on an npm or PyPI package version, asked before an agent installs it.
- Transport
- Not stated
- Package
- —
- Registry id
- ai.attestari/attestari
No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.
Attestari reads a package before an AI agent installs it. Attestari grades individual package versions, not projects. Attestari examines the file that a package manager downloads, not the GitHub repository.
Each finding includes the file, line, and exact text found. If a package cannot be examined, no grade is given and the reason is published. Publishers never pay for ratings; independence is maintained.
Attestari offers a device app and web app that show installed agent tools and their grades. Attestari uses four grades plus a 'not gradeable' outcome.
Summary drafted from the project's own website. Every sentence is backed by text on that page and was reviewed before publishing.