Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Back to the standard
rubric v1.0Disqualifying

Behaviour matches the manifest

The tools, scopes and destinations it declares are the ones it actually uses. Both directions count.

Applies to
agents, MCP servers, apps, templates
Standard references
none mapped

Why failing this one stops a sale

Almost nothing in this rubric is disqualifying. Most findings are information, published beside the badge and left to the buyer to weigh. This check is the exception, because software that does something other than what it declares is the shape of an attack rather than of untidy configuration, and no amount of disclosure makes that safe to sell.

Explainer · 2026-09-30

Behaviour matches the manifest: the one row that stops a sale, and why it is about honesty

Almost every finding here is information for a buyer to weigh. Software that does something other than what it declares is the exception, because that is the shape of an attack rather than of untidy work.

What this row checks

That the tools, scopes and destinations a listing declares are the ones it actually uses, in both directions. Doing something undeclared fails. So does declaring access it never uses, because an unused permission is a permission waiting for a reason.

What a mismatch looks like

One package removed from this catalogue described itself, in its own words, as a deliberately malicious server for testing. Its tool descriptions said one thing and its code another: a tool described as adding two numbers returned code, and others asked for API keys, passwords and card numbers. No description scanner would have flagged it, because the descriptions were bland. Holding the declaration against the behaviour is what catches it.

The quieter version is a rug pull: a server that declares one thing when it is approved and another on a later start or a later version. That is why a change in what a listing declares is treated here as a new product, not an update.

What can and cannot be checked

This row needs a manifest a maker has declared. A catalogue listing indexed from a public registry has none, so for it this row is not answerable, and the evidence map says so rather than showing a pass. It becomes answerable when a maker submits a listing with a manifest and it is run in the sandbox.

Sources

  1. Model Context Protocol specification: Tools
  2. Invariant Labs: MCP Security Notification, Tool Poisoning Attacks
  3. ooruby: what each kind of evidence can answer

In the glossary: Capability manifest, Rug pull, Permission drift.

What this check has found

Nothing in the catalogue has raised a finding on this check. That is a fact about what has been tested so far rather than a guarantee about what is out there, and it is printed because a check that never fires is worth knowing about too.

Other checks

No shipped credentialsDependency advisoriesDeclared egressData handling disclosedLicence and provenanceTransparency self-certification

Every listing in the catalogue shows its result on this check, with the findings summarised in public and the full report to whoever bought it. Open the catalogue.