About · the lab
An independent lab for AI-tool trust.
polygraph.so publishes behavioral security grades for MCP servers and static safety grades for Claude Code / Agent Skills — backed by evidence anyone can re-run.
What we do
Agents plug into third-party MCP servers and skills that can hijack them or leak data. We connect to those tools the way an agent would, exercise them, and watch what they actually do: whether their outputs try to hijack the caller, whether they reach out over the network when nothing required it, and whether data handed to them leaks back out. The result is a letter grade, A to F, published with the evidence behind it.
Servers are graded behaviorally by the open litmus harness (litmus-v17); skills are graded by a deterministic static scan (litmus-skill-v2). The full spec, including what a grade does and does not claim, is on the methodology page. Every published grade lives in the public index, free to read.
Why a grade can be trusted
The harness is open source and deterministic: the same server version and the same harness produce the same findings. Anyone — a skeptic, a counterparty, a graded vendor — can re-run it against the same server and compare. A false grade is falsifiable, not merely disputable. That reproducibility, plus a live fingerprint check that catches a server changing its tool surface after grading, is what the grade rests on.
The harness code is public at github.com/polygraphso/litmus and ships on npm as @polygraphso/litmus.
Independence and funding
Nobody can pay for a grade. No graded party gets review or approval rights over their result, and significant failures go to the vendor before they go public. Independence here is disclosure-based, not refusal-based: material relationships are stated publicly rather than pretended away.
The work is funded away from the grades. Public grades are free to read; ecosystem operators pay for continuous, per-network monitoring (see ecosystems), and the community-launched $POLYGRAPH token’s dev fees are claimed publicly and put toward the harness, the grades, and the evidence. The token funds the work; it doesn’t move a grade.
Who runs it
polygraph.so is built by the team behind Talent Protocol. Reach us at hello@polygraph.so or @polygraphso.