Every term that made you nod along
60 definitions written for the moment you have just been confused by one. Each says why it matters and names the specific mistake almost everybody makes with it.
- Terms defined
- 60
- Groups
- 4
- Cross references
- 208
Agents and protocols
10 termsAn open protocol that lets a model call external tools and read external data through a standard interface.
A program that exposes tools and data to a model through the Model Context Protocol.
Software that takes a goal, decides its own sequence of steps, and calls tools to carry them out.
The declared list of tools a listing exposes, scopes it needs and hosts it may contact.
Requiring a person to approve a specific class of action before an agent takes it.
The total amount of text a model can consider at once, including everything the tools put there.
The text an MCP server publishes about each of its tools, which the model reads to decide what to call and how.
The way a local MCP server talks to its client: over the standard input and output of a process the client starts.
The MCP transport for servers reached over the network, where the client sends each message to an HTTP endpoint.
An MCP server hosted by somebody else and reached over the network, rather than installed and run on your machine.
Trust and verification
16 termsWhen a new version of a listing quietly asks for more access than the version you approved.
The published set of tests a listing is put through, and the record of what they found.
The versioned list of checks verification runs, published in full.
The signed record of one verification run: what was tested, against which rubric, when, and what was found.
A listing that passed verification with issues recorded and published.
One issue raised by verification, with a severity and a mapping to a standard weakness class.
Running the rubric again, because the version changed, the rubric changed or the badge expired.
The share of tasks in our fixed set that a listing completed correctly, measured in the sandbox.
A key issued for one job, with only the access that job needs, that can be revoked on its own.
Installing one exact published release rather than whatever is current.
Checking software by reading its code rather than running it.
A finding that is not real: the check matched something that is not the problem it looks for.
The versioned list of rules this site uses to read MCP tool descriptions for instructions that do not belong there.
The kind of evidence a listing's results rest on, which decides which rubric rows can be answered at all.
A cryptographic fingerprint of the exact bytes that were checked.
A signed statement, published with a package, of which source repository and which build produced it.
Security findings
22 termsHiding instructions inside a tool description so the model reads them as commands.
Getting a model to follow instructions that arrive inside data it was asked to process.
Persuading a server to make a network request on your behalf, to somewhere you could not reach yourself.
An explicit list of the hosts a piece of software is permitted to contact.
When changing an identifier in a request lets you read somebody else's record.
Database rules that decide which rows a given user can see, enforced by the database itself.
Granting the narrowest access that makes the job possible, and nothing beyond it.
Everything a piece of software could reach if it were successfully turned against you.
A malicious server describing its tool so persuasively that the model prefers it to the legitimate one.
Tricking something that holds a privilege into using it for you.
Compromising something you already trust rather than attacking you directly.
Reaching outside the isolated environment something was supposed to be confined to.
A server that behaves well when it is approved and changes what it does or says afterwards.
When input from outside, such as a tool argument, ends up being run as part of a shell command.
A working key, token or password included in the files a package publishes.
Characters that take up no space on screen, used to hide text that a model will still read.
Moving data out of a system to somewhere its owner did not intend.
Publishing a package under a name one typo away from a popular one, to catch people who mistype it.
A public identifier for one specific, disclosed vulnerability in one product.
A catalogue of the kinds of mistake that cause vulnerabilities, each with a number.
Instructions planted in content a model reads while working, such as a web page, an email or a tool's output, rather than typed by the user.
A command a package tells the package manager to run automatically, for example straight after it is installed.
Buying and selling
12 termsRunning a listing on your own input, with no credentials and no payment, before you buy. Not available here yet.
Holding a payment after the sale and releasing it to the maker once the buyer has had time to check.
The period during which a buyer can return a listing and get their money back.
A reserve, funded from a share of every sale, that pays buyer claims after escrow has released.
A time-boxed process for resolving a purchase that did not go right.
A maker's refund rate, dispute rate and response time, published on their storefront.
A review written by someone who actually bought the listing, one per purchase.
A one-tap I want this or not for me, from anyone signed in, with no purchase required.
A public ask for something that does not exist yet, which other people can vote on.
Paying per run rather than per month, usually because the maker's own cost scales with use.
An outage that turns every failed task into several billed attempts, at once.
One of the first makers to sell here, on terms that last six months from joining.
Now go and use them
Every term above shows up on a real listing, next to a real result. Free to browse, no account needed.
Open the catalogue