The app catalog
The MCPTotal app catalog lists the MCP servers you can add to a space. This guide describes when and where the catalog is accessed, and the information it provides about MCP servers.
Open the app catalog
You access the app catalog from the main menu.
The app catalog is also displayed when you click Add in a space.
The app catalog
The main catalog (opened from the main menu) consists of:
- A tile to enable the addition of a custom MCP server.
- Tiles for custom apps.
- A search bar.
- A category list that filters the catalog. You can use this in combination with a search.
- Tiles for MCP servers.
The catalog view opens when you add an app to a space containing the search bar and app tiles. It doesn't include a category selector or support adding a custom app.
The app tile
The app tile in both catalog views includes:
- The app's icon, name, and provider.
- A badge indicating:
An MCP server developed and hosted by MCPTotal.
An MCP server developed and hosted by a service provider (first-party).
- The absence of a badge indicates that an MCP server is hosted by MCPTotal but developed by a third party.
- Badges indicating the status of non-MCPTotal developed servers:
The server is either an official provider's server or has been scanned and verified as safe for hosted development by MCPTotal.
The server may handle personally identifiable information.
The license governing use of the server.
The server is open-source, and the developers haven't updated it in more than 3 months.
Scans by MCPTotal indicate the server may request or expose more data than expected.
Scans by MCPTotal have identified critical vulnerabilities.
- A description of the app.
- Badges indicating the tools offered by the server.
- A button to add the app to an existing or new space.
In the main catalog, clicking on an app tile opens a full description of the server. In the catalog opened from the Add button in a space, clicking an app tile opens the add app dialog.
App information page
The app information page provides:
- Basic information about the app, such as its name and badge details as provided on its tile, and a button to add the app to an existing or new space.
- Tabs provide an expandable description of the MCP server (Description) and details about the server (Security), including package information, deployment safety, vulnerabilities, and more. For more details on the security tab content, see the App information page security tab.
- Details of any spaces where you have installed the app.
- A summary of the MCP server's security details.
- For a server developed by MCPTotal.
- For servers by other developers, a summary of the details provided in the security tab.
- For a server developed by MCPTotal.
- A list of the tools provided by the MCP server. Where the server includes several tools, the interface provides a search bar. You can expand each tool listing to reveal additional details about the capability it provides.
App information security tab
The app information security page provides information about an app's safety. The information presented depends on whether the app is:
- Developed by MCPTotal.
- An official server hosted by the provider.
- A third-party server.
Note: The MCPTotal AI agent scanner generates the information in this section. Be aware that the scanner can make mistakes.
MCPTotal developed servers
For an MCP server developed by MCPTotal, the app information security tab contains details about the server package, including:
- Package details, including the package name, a link to the MCPTotal website, and confirmation that MCPTotal developed the package.
- Confirmation that MCPTotal developed the server, along with a summary of the server's safety features and activities undertaken to maintain those safety features.
Official providers' servers
For an MCP server developed and hosted by a service provider, the app information security tab includes:
- Server details, including the server name, server URL, provider name, and confirmation that it is a remote MCP server.
- Confirmation that the server is a provider's official server, along with a summary of information on the server's hosting and how MCPTotal connects to that server.
- Details of the verifications performed by the MCPTotal AI agent.
Third-party servers
For third-party-developed MCP servers, the security tab includes a detailed summary of information gathered from scans of the MCP server performed by the MCPTotal AI agent.
Note: MCPTotal hosts each server in a space in an isolated, single-tenant sandbox, so the server doesn't have access to anything else you install in MCPTotal. Each server also runs as a private instance, so unless you share a space, no one else can access it and exploit any vulnerabilities in the source code or created by its dependencies.
However, if you share a space, those you share it with could exploit a vulnerability. Therefore, only share a space with people you trust.
- Package details, including the package name (and an icon indicating the package source, if any), a link to the source code, and confirmation of the scanning performed on the package.
- Deployment safety details
Details about excessive access - Results of a scan for malicious code by MCPTotal.
Note: MCPTotal won't host a server that includes malicious code. This section confirms that MCPTotal has performed malicious code scans and detected no issues. - Information about vulnerabilities discovered during scans performed by MCPTotal.
Details on each vulnerability include:- A lozenge indicating the severity of the vulnerability: critical, high, medium, low, or info.
- A reference code and sequential number for the item.
- An AI-generated summary description of the vulnerability.
- The location of the vulnerability in the source code.
- An expandable section containing an AI-generated description of the vulnerability.
- Information on PII exposure discovered during scans performed by MCPTotal. Details on each PII exposure include:
- A reference code and sequential number for the item.
- An AI-generated summary description of the PII exposure.
- The location of the PII exposure in the source code.
- An expandable section containing an AI-generated description of the PII exposure.
- Non-human identities discovered during MCPTotal scans. Details on each non-human identity include:
- A reference and sequential number for the item.
- An AI-generated summary description of the non-human identity.
- The location of the non-human identity's definition in the source code.
- An expandable section containing an AI-generated description of the non-human identity.
- Endpoints scanned by the MCPTotal AI agent.
- Dependencies discovered during scans performed by MCPTotal. Details on each dependency include:
- A lozenge indicating the potential for dependency to create a vulnerability, with levels: critical, high, medium, low, and info.
- A reference code and sequential number for the item.
- An AI-generated name for the dependency.
- The location of the dependency in the source code.
- An expandable section containing an AI-generated description of the dependency.