Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/CSOAI-ORG/firmware-attestation-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/mcp/csoai-org/firmware-attestation-mcp/firmware-attestation-mcp)<a href="https://agentmods.dev/mcp/csoai-org/firmware-attestation-mcp/firmware-attestation-mcp"><img src="https://agentmods.dev/badge/mcp/csoai-org/firmware-attestation-mcp/firmware-attestation-mcp/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/mcp/csoai-org/firmware-attestation-mcp/firmware-attestation-mcp"><img src="https://agentmods.dev/badge/mcp/csoai-org/firmware-attestation-mcp/firmware-attestation-mcp.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
firmware-attestation-mcp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"firmware-attestation-mcp": {
"command": "uvx",
"args": [
"firmware-attestation-mcp"
],
"env": {}
}
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 9 lines scan A 51373bebf5e3
firmware-attestation-mcp is an MCP server published in the GitHub repository CSOAI-ORG/firmware-attestation-mcp (0 stars, last pushed 2mo ago), licensed MIT. Its token cost is not measured: an MCP server costs its tool schemas, not its config file. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other mcp servers, from other repositories
c2pa-watermark-mcp
C2PA Watermark & Provenance MCP server. Built with c2pa-python. Runs locally from the c2pa-watermark-mcp Python package.
meok-eu-platform-worker-mcp
EU Platform Workers Directive (2024/2831) compliance — employment-status presumption, algorithmic-management disclosure, human oversight of significant decisions, worker data protection, member-state transposition tracking, misclassification-risk forecast. Targets EU gig-economy platforms (€20bn market). Transposition…
meok-ev-recall-transport-mcp
EV-recall transport compliance — ADR Class 9 (UN3480/3481/3536/3556/3557/3558), DGSA workflow, thermal-runaway routing, OEM recall protocols. For UK car transporters under ADR 2025 + ZEV Mandate. By MEOK AI Labs. Runs locally from the meok-ev-recall-transport-mcp Python package.
meok-imo-marpol-marine-mcp
IMO MARPOL + marine fuel + container ship compliance MCP. MARPOL Annex VI, EU ETS maritime, CII, EEXI, IMDG, bunker fuel, ballast water, Port State Control. For short-sea operators, RoRo car carriers, Channel freight, container shipping. By MEOK AI Labs. Runs locally from the meok-imo-marpol-marine-mcp Python package.
meok-rail-freight-uk-mcp
UK rail freight compliance — ORR licensing, ROGS safety certificate, Railway Interoperability Regulations 2011, TSI LOC&PAS/WAG, RID dangerous goods, ORR 14 Major Issues inspection prep, Network Rail capacity access. By MEOK AI Labs. Runs locally from the meok-rail-freight-uk-mcp Python package.
meok-vehicle-handover-mcp
Vehicle handover compliance — NAMA Vehicle Grading, BVRLA Fair Wear & Tear, photographic POD validation, RHA liability cap, BVRLA DRS dispute pack. For UK car-transport operators. Avoids £8k/mo chargebacks on a 100-vehicle fleet. By MEOK AI Labs. Runs locally from the meok-vehicle-handover-mcp Python package.