Verification
The published set of tests a listing is put through, and the record of what they found.
Verification covers secrets in shipped code and repository history, dependency advisories, licence and provenance disclosure, and whether a listing behaves as its manifest declares. MCP servers add SSRF, tool poisoning, command execution and authentication checks. Agents add a measured run against a fixed task set.
Every result is recorded against one version, with the rubric version used, and it expires.
It is the only question in this market nobody else answers, and it is the reason this site exists.
Reading a badge as a warranty. It is a record of what specific tests found on a specific day, and every badge on the site prints what it does not cover.
Related terms
See Verification on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue