Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell

Immutable rubric record

Current

Verification rubric v1.0

This is the exact public rule set receipts for v1.0 bind to. Its frozen snapshot, RFC 8785 form and domain-separated SHA-256 digest remain available even after a newer rubric becomes current.

sha256:7e317e8931ac1c39366decbf784d00f928c086a715d73c703a62969ec12a0d73

  1. 01

    No shipped credentials

    No API keys, tokens or passwords in shipped files or in repository history.

    secrets
  2. 02

    Dependency advisories

    Known vulnerable dependency versions, with severity and whether the affected path is reachable.

    dependencies
  3. 03

    Behaviour matches the manifest

    The tools, scopes and destinations it declares are the ones it actually uses. Both directions count.

    manifestdisqualifying
  4. 04

    Declared egress

    An explicit list of hosts it may contact, resolved rather than taken on trust.

    egress
  5. 05

    Data handling disclosed

    What it reads, what it writes, what it sends and to whom, stated in the listing.

    data_handling
  6. 06

    Licence and provenance

    Declared licence, open-source dependencies disclosed, and the tool it was built with named.

    licence
  7. 07

    Transparency self-certification

    The maker's own statement about AI transparency obligations. Recorded, not assessed by us.

    ai_transparency
  8. 08

    URL handling

    Any tool accepting a URL refuses internal and metadata addresses, including after a redirect.

    ssrfmcp_server
  9. 09

    Tool description integrity

    No instructions hidden in tool descriptions, which a model reads as commands.

    tool_poisoningmcp_server
  10. 10

    Command execution is bounded

    A fixed set of named commands rather than an interface that runs whatever string it is handed.

    command_execmcp_server
  11. 11

    Authentication enforced

    Privileged tools require authentication and enforce it on every path, not just the documented one.

    authmcp_server
  12. 12

    Measured run

    Run against a fixed task set. Success rate, median time and cost per run recorded, never estimated.

    sandbox_runagent
  13. 13

    Fails closed

    On uncertainty it stops and says so rather than proceeding on a guess.

    fail_closedagent
  14. 14

    Row-level security

    The database refuses rows the current user is not entitled to, verified with two accounts.

    rlsapp
  15. 15

    Object-level authorisation

    Changing an identifier in a request does not return somebody else's record.

    bolaapp
  16. 16

    CORS configuration

    Cross-origin access is restricted to the origins that need it.

    corsapp
Canonical rubric JSON
{"checks":[{"blurb":"No API keys, tokens or passwords in shipped files or in repository history.","key":"secrets","label":"No shipped credentials","maps":["CWE-798","CWE-540"]},{"blurb":"Known vulnerable dependency versions, with severity and whether the affected path is reachable.","key":"dependencies","label":"Dependency advisories","maps":["CWE-1395"]},{"blurb":"The tools, scopes and destinations it declares are the ones it actually uses. Both directions count.","disqualifying":true,"key":"manifest","label":"Behaviour matches the manifest"},{"blurb":"An explicit list of hosts it may contact, resolved rather than taken on trust.","key":"egress","label":"Declared egress","maps":["CWE-918"]},{"blurb":"What it reads, what it writes, what it sends and to whom, stated in the listing.","key":"data_handling","label":"Data handling disclosed"},{"blurb":"Declared licence, open-source dependencies disclosed, and the tool it was built with named.","key":"licence","label":"Licence and provenance"},{"blurb":"The maker's own statement about AI transparency obligations. Recorded, not assessed by us.","key":"ai_transparency","label":"Transparency self-certification"},{"blurb":"Any tool accepting a URL refuses internal and metadata addresses, including after a redirect.","key":"ssrf","kinds":["mcp_server"],"label":"URL handling","maps":["CWE-918"]},{"blurb":"No instructions hidden in tool descriptions, which a model reads as commands.","key":"tool_poisoning","kinds":["mcp_server"],"label":"Tool description integrity"},{"blurb":"A fixed set of named commands rather than an interface that runs whatever string it is handed.","key":"command_exec","kinds":["mcp_server"],"label":"Command execution is bounded","maps":["CWE-78"]},{"blurb":"Privileged tools require authentication and enforce it on every path, not just the documented one.","key":"auth","kinds":["mcp_server"],"label":"Authentication enforced","maps":["CWE-306"]},{"blurb":"Run against a fixed task set. Success rate, median time and cost per run recorded, never estimated.","key":"sandbox_run","kinds":["agent"],"label":"Measured run"},{"blurb":"On uncertainty it stops and says so rather than proceeding on a guess.","key":"fail_closed","kinds":["agent"],"label":"Fails closed"},{"blurb":"The database refuses rows the current user is not entitled to, verified with two accounts.","key":"rls","kinds":["app"],"label":"Row-level security","maps":["CWE-285"]},{"blurb":"Changing an identifier in a request does not return somebody else's record.","key":"bola","kinds":["app"],"label":"Object-level authorisation","maps":["CWE-639"]},{"blurb":"Cross-origin access is restricted to the origins that need it.","key":"cors","kinds":["app"],"label":"CORS configuration","maps":["CWE-942"]}],"version":"1.0"}

Version archive

Released snapshots, oldest to newest

1 version
v1.0 · current
Read the human methodology →Browse signed receipt history →