Hi ToolHive / Stacklok team π
I maintain HVTracker (hvtracker.net), an independent trust registry for open-source AI-agent and MCP tooling, scored on public supply-chain signals. (Disclosure: I run it β heads-up from the author.) As folks who build security tooling, you'll recognize the inputs.
ToolHive scores Grade B, 70.9/100, with an OpenSSF Scorecard of 8.1/10 and 100% signed commits β strong, as you'd expect from Stacklok. Full breakdown: https://hvtracker.net/agents/toolhive/
The gap to Grade A is build provenance β SLSA/attestations on the Go release artifacts would close most of it (right up your alley). If a self-updating HVTrust badge is useful alongside your other signals:
[](https://hvtracker.net/agents/toolhive/)
Optional, and I'll fix anything we scored wrong. Thanks for pushing secure-by-default MCP tooling.
Hi ToolHive / Stacklok team π
I maintain HVTracker (hvtracker.net), an independent trust registry for open-source AI-agent and MCP tooling, scored on public supply-chain signals. (Disclosure: I run it β heads-up from the author.) As folks who build security tooling, you'll recognize the inputs.
ToolHive scores Grade B, 70.9/100, with an OpenSSF Scorecard of 8.1/10 and 100% signed commits β strong, as you'd expect from Stacklok. Full breakdown: https://hvtracker.net/agents/toolhive/
The gap to Grade A is build provenance β SLSA/attestations on the Go release artifacts would close most of it (right up your alley). If a self-updating HVTrust badge is useful alongside your other signals:
Optional, and I'll fix anything we scored wrong. Thanks for pushing secure-by-default MCP tooling.