← MCP Scorecard · rated by proofof.ai

sigstore-cosign-mcp

Sigstore cosign + rekor transparency log verification for signed container images + git tags + b...

90/100  A+  · ranked #76 of 339 MEOK MCPs · v1.0.3 · 5 tools

Is sigstore-cosign-mcp production-ready?

sigstore-cosign-mcp scores 90/100 on the proofof.ai 100-point rubric — flagship-grade (top tier). That is above the fleet average of 85. Install: pip install sigstore-cosign-mcp.

How does sigstore-cosign-mcp score across the 10 categories?

CategoryScore
README10/10
Tool design10/10
Examples10/10
Tests + CI10/10
Transports5/10
Metadata10/10
Reliability8/10
Security10/10
Docs surface7/10
Provenance/Revenue10/10

What can sigstore-cosign-mcp do?

Framework: fastmcp · transport: stdio. Tools: verify_image_signature, query_rekor_log, verify_attestation, check_keyless_identity, list_trusted_certs.

How to install sigstore-cosign-mcp

pip install sigstore-cosign-mcp

MCP client config: add {"command":"uvx","args":["sigstore-cosign-mcp"]} under mcpServers.

Links