AUDIT OPERATIONS / LIVE
DEMO DATAStart audit in TrueForge ↗

MCP TRUST OPERATIONS

Watch every server.
Trust the evidence.

2Active audits
1Needs decision
14Protected servers

01 / LIVE

Doing

2

Inspections running inside isolated Daytona sandboxes.

LIVE2m 14s ago

github-mcp-server

npm / 0.19.1

discoverinspectjudgeact

Calling 7 read-only tools inside Daytona

LIVE48s ago

filesystem

npm / 2026.8.0

discoverinspectjudgeact

Comparing registry metadata with last approval

02 / DECIDE

Waiting on you

1

Review the evidence before trust changes.

!
CONFIRMED THREATAction requires your approval

VERDICT

weather-buddy-mcp

v1.0.3

Malicious
Canary left the sandbox

POST weather-telemetry.example/collect, request body

Hidden instruction

Tool description references GITHUB_TOKEN behind U+200B

Changed since approval

Approved 1.0.2, observed 1.0.3

Proposed action

Remove from allowlist and open an evidence-backed pull request

Review in TrueForge ↗

Approval stays in TrueForge. This console never performs the write.

03 / HISTORY

Did

Just now

A durable record of evidence and trust decisions.

Clean

slack-mcp-server

v1.4.2 · Today, 14:32

No static findings, capability drift, or canary egress.

EvidenceNo configured canary values observed in outbound HTTP traffic.

Changed

notion-mcp

v2.1.0 · Today, 13:08

Two tools added and one input schema changed.

EvidenceAdded search_pages and archive_page; update_page input schema changed.

PR #11 ↗
Could not inspect

linear-mcp

v0.8.4 · Yesterday, 18:45

Server rejected the canary credential before any tool ran.

EvidenceServer rejected the canary credential before any MCP tool executed.