MCP servers › io.github.svayatta › agent-custody
MCP server · registry snapshot 2026-10-04
io.github.svayatta/agent-custody
MCP gateway that checks each agent tool call against a signed grant and policy, and signs a receipt — the publisher's description
Summary
io.github.svayatta/agent-custody is a local MCP server listed in the official MCP registry at version 0.6.15. We have not tested it. It requires a setting the publisher marks as required (for example a URL part or a configuration value) that has no default, so we did not start it.
Key facts
- Runs
- local package
- Transport
- standard input/output
- Package
- npm · listed version behind the latest release
- License
- Apache-2.0
- Dependencies
- no known high or critical advisories
- Repository
- public
- Topic
- securityAI-classified
- Pricing
- freemiumAI-classified
- Last tested
- not tested
Worth knowing before you connect it
- The registry lists 0.6.15; 0.6.18 is newer (3 releases).
Each line comes from a section below, with its source and date.
How fresh this is
- Live-tested
- no
- Last tested
- not tested
- Registry data
- snapshot 2026-10-04
- Package and repository
- checked 2026-10-06
Security testing
Has it been tested?
Feature #1It requires a setting the publisher marks as required (for example a URL part or a configuration value) that has no default, so we did not start it.
What it is
Does the registry listing match what we found?
Feature #6The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.
| Registry says | We found | Result | Source · date |
|---|---|---|---|
| Version 0.6.15 on npm | Exists and can be installed | matches | npm · 2026-10-06 |
| Repository github.com/svayatta/agent-custody | Opens publicly | matches | api.github.com · 2026-10-06 |
Can it be installed, and is it up to date?
Version pin · advisories
Listed version
- Registry lists
- 0.6.15
- Latest stable
- 0.6.18
- Status
- behind the latest release (3 releases, 1 days)
- Withdrawn
- no
Source: registry.npmjs.org · 2026-10-06. About the version the registry lists; a manual install may resolve to a different one.
Dependency advisories
Counted in the full dependency tree as resolved on 2026-10-08 (npm audit). Bars share one scale. The package itself has no known vulnerability (OSV.dev).
Integrity, provenance, license
- Integrity
- sha512-2iD5Mk+0MDuLfLETT…
- Signature
- signed
- License
- Apache-2.0
Source: the package registry · 2026-10-06.
Usage
- Downloads
- 5,501 in the last month
Source: api.npmjs.org · 2026-10-06.
Who made it?
Feature #7 · lineage
Facts about the publisher. We do not turn them into a trust score.
- Namespace
- io.github.svayatta
- GitHub owner
- an organization (svayatta)
- Build record
- signed
- Repository
- github.com/svayatta/agent-custody
- Stars
- 8
- Repository age
- 31–90 days
- Last push
- 0–30 days ago
- Archived
- no
Source: the registry entry and api.github.com · 2026-10-06.
Choosing
Common questions about io.github.svayatta/agent-custody
Answered from the data aboveIs io.github.svayatta/agent-custody free to use?
Its website (agent-custody.dev/) describes a freemium pricing model. This is an AI-classified reading of the page on 2026-10-08, so check the page itself before relying on it.
Has io.github.svayatta/agent-custody been security tested?
Not yet. It requires a setting the publisher marks as required (for example a URL part or a configuration value) that has no default, so we did not start it.
Is the listed version current?
No. The registry lists 0.6.15; the latest stable release on npm is 0.6.18.
Where is the source code of io.github.svayatta/agent-custody?
In github.com/svayatta/agent-custody, which opens publicly.
Reference
How is it classified?
18 fields
One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.
“The hosted log is free to ten thousand appends a month.”
“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.
Cite or correct this page
Sources and corrections
Suggested citation
ProtocolProbe. “io.github.svayatta/agent-custody: MCP server record.” Data checked 2026-10-06. https://protocolprobe.com/mcp/servers/io.github.svayatta/agent-custody
Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.
As JSON: this record in the API · API documentation.
Something wrong, or is this yours?
If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.
Write to hello@protocolprobe.com · corrections log · methodology