polygraphso/Polygraph MCP gate

Fail the build if an MCP dependency grades D/F under the open polygraph behavioral litmus.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
serversExplicit MCP refs to check (newline- or comma-separated). Merged with auto-discovery.no""
skillsExplicit skill directories to grade (newline- or comma-separated). Merged with auto-discovery.no""
discoverAuto-discover targets from MCP config files (.mcp.json, .vscode/mcp.json, .cursor/mcp.json). OFF by default — opt in only on trusted repos, since discovered targets are PR-controllable and grading runs their code.nofalse
min-gradeMinimum acceptable grade (A|B|C|D). Default gates on D/F.no""
strictTreat un-gradeable dependencies as failures instead of warnings.nofalse
working-directoryDirectory to scan for MCP config files.no.
version@polygraphso/litmus version to run.no0.36.0
api-urlOverride the published-grade lookup API base URL. HTTPS is enforced (http only for localhost). Point only at the official endpoint or a mirror you trust — an attacker-controlled endpoint can return fabricated grades.no""
bearerBearer token sent as an Authorization header to a gated remote (https) target. Only for an explicitly trusted, pinned remote — never with discovery or on untrusted PRs; keep it scoped and short-lived.no""
namedescription
resultpass or fail
failedNumber of dependencies that tripped the gate
reportJSON array of per-target results