Skip to content
surex
ILLUSTRATIVE DATA · LOCAL FIXTURESThe registry API is not reachable, so this page is rendering local fixtures. Every server, verdict, finding, blob ID and transaction digest below is placeholder content. Nothing here is a real review of a real MCP server.REGISTRY UNREACHABLE: The operation was aborted due to timeout
surex.dev/r/sxf1_41c09ae290bd3117…20e4f6b3
REGISTRY UNREACHABLE · The registry API did not answer. The gate fails open with a warning; it never silently blocks, and never silently clears something it had already flagged.
CLEAN
TIER A · RECORDED DIGEST MATCHES THE REVIEWED BLOB
UNCONTESTED SINCE 2026-05-02

mcp-server-postgres 0.6.2

npm · @modelcontext/postgres · fingerprint sxf1_41c09ae2…4f6b3

IN TWENTY SECONDS

An automated review found nothing beyond this server’s stated purpose, and nobody has contested that in 84 days. That is the whole claim: the capability surface below is often more useful than the verdict.

Read what the code can reach. This page is linked from the registry, not from a block.

LINKAGE · WHAT THIS VERDICT IS ABOUT VS WHAT YOU INSTALLEDthe registry never sees your machine; the gate compares digests locally and keeps the answer there
REVIEWED BLOB
walrus:0x11c4…77e0
YOUR INSTALL
recorded digest matches
Athe reviewed bytes are the bytes recorded for your version
FINDINGS

None recorded. That is a statement about what the model saw, at that commit, at that time. Read the capability surface below for what this code can reach. It is usually the more useful half.

CAPABILITY SURFACEwhat the reviewed code can reach, from a static scan that does not ask the server what it does. Shown on clean verdicts too.
networkthe configured database host onlysrc/client.ts:44
filesystemreads and writes ./migrationssrc/migrate.ts:12
process execnot present in the reviewed blob
env variablesPG* connection variables onlysrc/env.ts:8
credentialsthe connection string, which stays in-processsrc/env.ts:9
This code can reach: network · filesystem · environment variables · credential stores
PROVENANCE · WHAT WAS REVIEWED, WHEN, BY WHAT
COMMITa90bd31145 (tag v0.6.2)
REVIEWED2026-05-02 09:41 UTC
SOURCE BLOBwalrus:0x11c4…77e0
MODELqwen3-coder-480b
PROMPTp7 · 3 passes
INTEGRITYsha512-41c09ae2…
INDEXarkiv:verdictHead/41c09ae2
VERDICT BLOBwalrus:0x90b2…4a11
Any Ethereum client can read this verdict from the name above, and the response carries a signature made by the key the resolver names. That signature says the answer came from SureX. It does not say the review is right, and the gate that blocks tool calls does not read it. getEnsText({ name, key: 'surex:state' })
This review was automated. No human audited this code. The model and prompt version above produced every word of the finding.
WHAT CLEAN MEANS HERE

This submitted version, read statically, showed no model-detectable mismatch between its stated purpose and its code, at that time. It does not cover dependencies, and it does not mean the copy installed on your machine is the copy that was reviewed.

The gate passes calls to this server without comment while the verdict holds. When a newer release ships, this verdict goes stale until the new blob is reviewed.

DISAGREE WITH THIS VERDICT?

Anyone with standing can contest it: the maintainer, a user, or an agent that depends on this server. Rebuttals are stored as their own blob and shown beside the accusation with equal weight.

File a dispute

mcp-server-postgres · verdicts are superseded, never deleted

source blobs: Walrus on Suiverdict index: Arkivpersonhood: World IDagent identity: World AgentKitverdicts are superseded, never deleted