PluginBench
MCP Server
Maintained
Apache-2.0

io.github.polygraphso/litmus MCP Server

io.github.polygraphso/litmus

Grade MCP servers A–F with the open behavioral litmus harness — reproducible, deterministic, and runnable from your agent.

What is the io.github.polygraphso/litmus MCP server?

The litmus MCP server is an open behavioral grading harness that evaluates MCP servers on a scale of A–F by connecting as an agent would, fingerprinting their tool surface, and running four probe categories: tool-output injection, permission/egress, sensitive-data handling, and adversarial-input handling. It ships as an npm package with a CLI, an MCP server for agent integration, and a GitHub Action for CI gating. The hosted endpoint serves fast grade lookups; the local install runs the full harness to grade servers immediately.

Litmus grades MCP servers reproducibly by executing them in a sandboxed environment and probing for injection vulnerabilities, permission leaks, data-handling risks, and input-handling flaws. Use it to vet servers before installation, gate CI on grade thresholds, or integrate grading into your agent workflows. The same package also grades Claude Code / Agent Skills with a static litmus scan.

How to install io.github.polygraphso/litmus

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • POLYGRAPH_API_URL

    Base URL for published-grade lookups (check_server, list_servers, request_grade) and attestation resolution.

  • NEXT_PUBLIC_POLYGRAPH_NETWORK

    Which network to read attestations from: 'base' (mainnet, default) or 'base-sepolia' (testnet).

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "litmus": {
      "command": "npx",
      "args": [
        "-y",
        "@polygraphso/litmus",
        "polygraphso-litmus-mcp"
      ],
      "env": {
        "POLYGRAPH_API_URL": "<YOUR_POLYGRAPH_API_URL>",
        "NEXT_PUBLIC_POLYGRAPH_NETWORK": "<YOUR_NEXT_PUBLIC_POLYGRAPH_NETWORK>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • check_server — Read a server's published grade in under a second without execution; pre-flight check before recommending or installing.
  • list_servers — List servers with published grades (A first), paged with filters by grade, limit, and offset; includes full-corpus summary.
  • request_grade — Record a grade request with polygraph.so ($1 one-time fee; graded within 48h of payment).
  • run_litmus — Grade a server now: run the full harness locally, returning grade and evidence bundle to the agent.
  • run_skill_litmus — Grade a Claude Code / Agent Skill with static scan (A/B/D/F), checking for prompt injection, data exfiltration, and dangerous commands.
  • verify_attestation — Read the onchain proof behind a published grade (EAS attestation on Base).

Use cases

  • Vet an MCP server's security posture before installing it in your agent or CI pipeline.
  • Gate a GitHub Actions workflow on MCP server grades (D/F fail by default; configurable threshold).
  • Grade a custom MCP server or Claude Code Skill to measure its behavioral safety and reproducibility.
  • Look up published grades for servers in the polygraph.so index to compare and recommend safe integrations.
  • Integrate server grading into your agent's decision logic to auto-select or reject unsafe tools.

io.github.polygraphso/litmus MCP server FAQ

What does litmus grade?

MCP servers (npm, PyPI, GitHub, or https endpoints) and Claude Code / Agent Skills. It runs four probe categories: tool-output injection, permission/egress (Docker-sandboxed), sensitive-data handling, and adversarial-input handling. Skills are graded with a static scan (no execution).

Is litmus free?

The npm package and CLI are free and open-source (Apache-2.0). Looking up published grades is free. Running the full harness locally is free. Requesting a new grade from polygraph.so costs $1 one-time and is graded within 48h.

How do I use it in Claude or Cursor?

In Claude Code, run `/plugin marketplace add polygraphso/litmus` then `/plugin install polygraph@polygraphso` for `/polygraph:grade` and `/polygraph:check` commands. For Cursor or manual JSON config, add the hosted endpoint `https://polygraph.so/api/mcp` as an http MCP server, or install the npm package locally for the full toolset.

Does it require authentication?

The hosted endpoint (grade lookups only) requires no auth. The npm package runs locally and can optionally accept a `bearer` token for authenticated remote endpoints. The GitHub Action accepts an optional `bearer` input for trusted, pinned remotes.

What does a grade mean?

A–F is a reproducible behavioral measurement: A is static-clean and passes all probes; B passes with minor findings; C has moderate findings; D has significant findings; F fails. A passing grade is a measurement, not a guarantee. Re-run the open harness to reproduce or refute any result.

Does it run the server's code?

Yes. The harness connects as an agent would and executes the target server. Egress is Docker-sandboxed (default-deny, matched host and port). Without Docker, C-02 (egress) is skipped and the grade caps at B. For skills, grading is static (no execution).

README (reference)

Source of truth, from the repository.

<img src="https://www.polygraph.so/brand/mark.png" alt="polygraph" height="56" />

litmus

The open behavioral litmus harness for MCP servers — grade A–F, reproducible.

<!-- Badges live in a one-row table so they stay on a single line on BOTH the repo page and the GitHub Marketplace listing for the polygraph-mcp-gate action. The Marketplace stylesheet sets `img { display: block }`, which stacks plain inline badges into a tall vertical column; table cells lay out horizontally regardless. GitHub strips inline styles, so the cells keep their default 1px border — that boxed look is expected. Don't revert to a plain badge line. --> <table> <tr> <td><a href="https://www.npmjs.com/package/@polygraphso/litmus"><img alt="npm" src="https://img.shields.io/npm/v/@polygraphso/litmus?style=flat-square&amp;labelColor=0d1117&amp;color=6f42c1" /></a></td> <td><a href="https://github.com/polygraphso/litmus/actions/workflows/ci.yml"><img alt="CI" src="https://img.shields.io/github/actions/workflow/status/polygraphso/litmus/ci.yml?branch=main&amp;style=flat-square&amp;labelColor=0d1117&amp;label=ci" /></a></td> <td><a href="LICENSE"><img alt="license" src="https://img.shields.io/badge/license-Apache--2.0-555?style=flat-square&amp;labelColor=0d1117" /></a></td> <td><a href="https://glama.ai/mcp/servers/polygraphso/litmus"><img alt="Glama" src="https://glama.ai/mcp/servers/polygraphso/litmus/badges/score.svg" /></a></td> <td><a href="https://smithery.ai/servers/ruben-sousa-dinis/polygraphso"><img alt="Smithery" src="https://smithery.ai/badge/ruben-sousa-dinis/polygraphso" /></a></td> <td><a href="https://polygraph.so/mcp/npm/@polygraphso/litmus"><img alt="graded by polygraph" src="https://polygraph.so/api/badge?server=npm/@polygraphso/litmus" /></a></td> </tr> </table>

Grade a server in one command

# -p is required: the package ships three bins, so npx must be told which to run
npx -y -p @polygraphso/litmus polygraphso-litmus litmus npm/@modelcontextprotocol/server-filesystem

Point it at an npm ref, a pypi ref, a github/owner/repo ref (cloned, built, and run sandboxed — Docker required; the grade pins the commit SHA), an https:// MCP endpoint, or a local entry file. The harness connects the way an agent would, fingerprints the exact tool surface, runs the four probe categories, and prints the grade with the findings behind it — plus a deterministic evidence bundle on disk. It runs the target's code (egress is Docker-sandboxed; without Docker, C-02 is skipped and the grade caps at B), takes ~20–60s, and exits non-zero on D/F so it scripts anywhere. To dispute any published grade, re-run this same command against the same server — open and deterministic means a re-run reproduces the grade, or refutes it.

Looking up a grade someone already published takes under a second and runs nothing: the polygraph.so index, or check_server from the MCP tools below.

litmus grading npm/@modelcontextprotocol/server-filesystem — five probe steps, then grade: A

Use it from your agent — MCP server + plugin

For grade lookups, point any MCP client at polygraph's hosted endpoint, no install:

claude mcp add --transport http polygraph https://polygraph.so/api/mcp

or the raw config:

{ "mcpServers": { "polygraph": { "url": "https://polygraph.so/api/mcp" } } }

This serves the lookup tools only (check_server, list_servers, request_grade); grading a server yourself (run_litmus, run_skill_litmus) executes its code, so it needs the local stdio install below.

The package also ships a stdio MCP server (polygraphso-litmus-mcp) with the full toolset, for any MCP-capable client:

  • check_server — read a server's published grade in under a second (no execution); the pre-flight check before recommending or installing a server.
  • list_servers — servers with a published grade, A first; paged (default 25 per call, with grade/limit/offset filters and a full-corpus summary).
  • request_grade — record a grade request with polygraph.so ($1 one-time fee; graded within 48h of payment — the response carries the payment link).
  • run_litmus — grade a server now: the full harness, grade + evidence returned to the agent.
  • run_skill_litmus — grade a Claude Code / Agent Skill (static scan, A/B/D/F).
  • verify_attestation — read the onchain proof behind a published grade (EAS on Base).

In Claude Code, the plugin wires the server plus two commands in one step:

/plugin marketplace add polygraphso/litmus
/plugin install polygraph@polygraphso

then /polygraph:grade <server> and /polygraph:check <server>. Cursor and manual JSON setups are on polygraph.so; full tool docs in packages/litmus/README.md.

Gate your CI on MCP grades — GitHub Action

Fail a build when an MCP server or an Agent Skill it ships grades D/F under the open behavioral litmus. For servers it is hybrid — a fast lookup of the published grade, then the harness when ungraded; for skills it is a fast static scan. Un-gradeable targets warn unless strict.

It's on the GitHub Marketplace as polygraphso/litmus@v1. For a security gate, pin to a commit SHA rather than the mutable @v1 tag:

# .github/workflows/mcp-gate.yml
name: mcp-gate
on: [pull_request]            # NOT pull_request_target — that exposes secrets to fork PRs
permissions:
  contents: read
jobs:
  gate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
      - uses: polygraphso/litmus@<commit-sha>   # pin to a SHA; resolve from the v1 release
        with:
          # Name the targets explicitly (recommended). Grading runs a server's code,
          # so on a public repo prefer an allowlist over discovering PR-controlled config:
          servers: |
            npm/@modelcontextprotocol/server-filesystem
          skills: |
            ./my-skill
          # discover: "true"  # opt in to auto-discovery (.mcp.json/.vscode/.cursor) — trusted repos only
          # min-grade: B      # stricter than the default D/F gate
          # strict: "true"    # also fail on targets that cannot be graded

Inputs: servers · skills · discover (default false) · min-grade · strict · working-directory · version · bearer. Outputs: result · failed · report.

Security. Grading a server runs its code (egress is Docker-sandboxed, but it still executes). Trigger on pull_request, never pull_request_target. Keep discover off on public repos and name targets explicitly — auto-discovered config is pull-request-controllable. bearer is sent as an Authorization header to the target, so pass it only for an explicitly trusted, pinned remote — never with discovery or on untrusted PRs, and keep it scoped and short-lived.

Not on GitHub? The gate is a plain command — npx @polygraphso/litmus@0.20.0 ci (pin the version) — so it runs in any CI or as a pre-commit hook. A grade is a measurement, not a guarantee: re-run the open harness to reproduce any result.

What litmus is

This is the source for @polygraphso/litmus, the open behavioral litmus harness for MCP servers from polygraph.so.

The harness connects to an MCP server the way an agent would, fingerprints its exact tool surface, and runs four probe categories — C-01 tool-output injection (static, dynamic, and second-order — one tool's output weaponized as another's input), C-02 permission/egress (in a hardened default-deny Docker sandbox, matched host and port), C-03 sensitive-data handling (planted canaries), C-04 adversarial-input handling (malformed/oversized and jailbreak inputs) — then grades the server A–F. A passing grade is a measurement, not a guarantee; the methodology and its disclosed limits are at polygraph.so (the open source here is the ground truth).

Alongside the grade, an npm target's dependency tree is checked against the osv.dev vulnerability database and any vulnerable dependencies are reported as dependency advisories. This is a separate, point-in-time signal — it is advisory only: it never affects the A–F grade and is not part of the reproducible evidence (vulnerability data changes over time, so folding it into the grade would break re-run reproducibility). It applies to npm targets only; other target kinds report it as skipped. Resolution runs npm install --package-lock-only --ignore-scripts, which resolves the tree without downloading tarballs or running any package code. Opt out with --no-deps-audit (or LITMUS_DEPS_AUDIT=0).

The same package also grades Claude Code / Agent Skills (a SKILL.md + bundle) under a separate static litmus (litmus-skill-v3): a deterministic byte-scan — S-01 prompt injection, S-03 data-exfiltration instructions, S-04 dangerous commands in the SKILL.md body or bundled scripts (incl. base64-obfuscated curl | bash) — graded A/B/D/F and anchored by a whole-directory content hash, plus a separate advisory quality signal. It is static (no execution): an A is static-clean, not behavioral proof. See packages/litmus/README.md.

The hosted, operator-run grading service is not in this repo — it lives in a separate private repo and consumes this package from npm like any other client.

Layout

This is a pnpm monorepo. Only @polygraphso/litmus is published; the @polygraph/* packages are private building blocks that tsup bundles into it.

packages/
  litmus/          # @polygraphso/litmus — the only published package (lib + 3 bins: CLI, skill CLI, MCP)
  core/            # contract types, canonical JSON, identity helpers
  probes/          # the harness: connect, fingerprint, grade, probe runners, sandbox
  onchain/         # EAS attestation read + encode/decode (Base) — read-only, no minting
  agent/           # agent-gate decision logic + live-fingerprint recheck
  mcp/             # MCP server wrapper
  cli/             # CLI commands + target/auth resolution
  demo-*-mcp/      # demo MCP servers used as test fixtures

See packages/litmus/README.md for the npm-facing usage docs, and polygraph.so for the methodology and proof format.

Develop

pnpm install
pnpm -r typecheck
pnpm -r test
pnpm --filter @polygraphso/litmus build   # → packages/litmus/dist

Release

@polygraphso/litmus is versioned in packages/litmus/package.json. Tag to publish:

git tag litmus-v<x.y.z> && git push origin litmus-v<x.y.z>

The Publish @polygraphso/litmus workflow builds, typechecks, tests, and publishes with npm provenance. See CONTRIBUTING.md for the full process and the local-development workflow for downstream consumers.

License

Apache-2.0 — © polygraph.so.

Related MCP servers

Coordination for parallel coding agents: file claims, enforcement hooks, git-native lessons.

Place/cancel/close HL perps via MCP. Agent wallet once, 1bp fills, no sub.

View repository →

AI job search agent — browse listings, generate packs, auto-apply

View repository →

Provides metadata information to AI agents through the search API.

View repository →

Fire one canonical conversion event to every ad platform's server-side Conversions API.

View repository →

Audit and generate agent-native product surfaces

0
TypeScript
MIT
View repository →