Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Free guide
All free tools & guides

Free guide

How to read a security finding without panicking or ignoring it

Findings are published on every listing here, including the awkward ones, and a published finding is not a warning label. It is the thing that lets you make a decision instead of a guess. This is how to make it.

2 min read · 6 sections

In this guide
  1. Severity is a ceiling, not a forecast
  2. Reachability is the field that decides it
  3. Then ask who supplies the input
  4. Check the date against the version
  5. A listing with findings is usually a better sign than one without
  6. Write down what you decided and why

Severity is a ceiling, not a forecast

A severity rating describes the worst outcome if the weakness is exploited in the most favourable conditions for an attacker. It says nothing about whether those conditions exist where you work.

So a critical finding in a code path you will never call is less relevant to you than a medium one in the feature you bought the software for. Reading the severity alone reliably produces both of the available mistakes: refusing something safe and installing something that is not.

Reachability is the field that decides it

Reachability answers whether the weakness sits in code your usage will actually execute, with inputs you will actually supply. A finding in an optional integration you are not enabling is not reachable.

This is why we publish the affected component rather than only the rating. Read the component first, decide whether you will touch it, and only then look at how bad it would be.

Then ask who supplies the input

A weakness that requires input from an untrusted source is a real risk if your agent reads email, web pages or customer documents, and close to theoretical if it only ever processes files your own team wrote.

For agents this is the question that moves fastest. A tool added six months after purchase can turn an unreachable finding into a reachable one without anything in the software changing.

Check the date against the version

A finding is about a version. If the maker has shipped twice since, the finding may be fixed or may have been joined by others, and the only honest position is that the badge no longer describes what you would install.

An old test date beside a recent update is the single combination that should stop you, regardless of what the findings say.

A listing with findings is usually a better sign than one without

Nothing here passes sixteen checks cleanly very often, and a long clean sheet more commonly means a thin piece of software with little surface than a carefully built one.

What matters is the maker's response: whether findings are acknowledged, whether they are fixed, and how long it took. That history is on the listing, and it predicts the next twelve months better than the current rating does.

Write down what you decided and why

One line, on the day: which findings you read, why you accepted them, and what would change your mind. It takes a minute.

In six months, when somebody asks why this is installed, that line is the difference between a decision and an accident. It is also the most useful thing you can hand to whoever replaces you.

Email me this guide

A copy for your inbox, plus one genuinely useful tool or guide occasionally. Unsubscribe any time.

No spam, no selling your address, unsubscribe in one click. The tools stay free either way.

Was this useful?

Educational information, not financial advice. Figures current as of July 2026 where dated; allowances and rates change, so check the source before acting.