close
Skip to main content
Every rule mcpscore runs, generated from the rule registry (make docs-rules) — this page cannot drift from the code.
  • Rule ID is the stable machine contract used in JSON reports and CI.
  • Weight is the severity’s contribution to the score when the rule passes.
  • Applies to is the spec-version range; outside it the rule is skipped and excluded from the maximum score (see the methodology).

Packaging rules

These rules apply only to mcpscore --package <coordinate>, which reads a published package’s registry metadata and never downloads or runs it. They are the only rules a package audit runs, and no server audit runs any of them — the two judge different targets, so their scores share no denominator. A package audit says how well a server is published; run the server with --stdio to score whether it speaks MCP.

Protocol Version

Server Info

Capabilities

Security

Tools

Transport

Resources

Resource Templates

Prompts

Readiness rules

These rules assess readiness for MCP 2026-07-28 on the independent readiness axis. For modern-lifecycle servers in full audits, they are also counted in the main score; legacy and partial audits keep them separate. See the methodology for the normative citations behind each rule.

Retired rules

These rule_ids no longer run. They are listed because a rule ID is a public contract: it appears in JSON reports you may have stored and in CI configuration that may still reference it. Retired IDs are never reused. A rule is retired only when it was wrong. A rule that was correct but applies only to certain spec revisions is not retired — it keeps its ID and gains a version range in the Applies to column above. If a report of yours shows one of these, its result was accurate for the mcpscore version that produced it; the check simply no longer exists.