The Trust Diff · free weekly email

What changed in the MCP trust landscape this week

New tools slipped into servers, install scripts that appeared overnight, maintainer flips, same-version republishes — caught by the MCP Skills version archive and delivered to your inbox every Tuesday. No hype.

Free. One email a week. Unsubscribe anytime. See past issues →

What's inside each issue

⚠️ Supply-chain watch — new and changed install scripts, maintainer flips, and same-version republishes across tracked MCP packages.
🔒 Security watch — new advisories (OSV / CISA KEV) affecting MCP servers and AI skills.
📈 Movers — the week's top MCP packages by npm downloads.
🆕 New in the registry — fresh servers added to the official MCP Registry.
🔭 Ecosystem pulse — spec updates and notable moves across the MCP world.
Trust spotlight — one repo worth knowing about before your agent installs it.

Every signal is backed by the same 15-signal trust scoring behind the scanner. Track the raw stream anytime at mcpskills.io/changes.