{"package":"mcp-trustcard","ecosystem":"npm","exists":true,"latest_version":"3.0.2","repository":"https://github.com/davidnichols-ops/trustcard","license":"MIT","description":"Cryptographic trust infrastructure for MCP servers — content-addressed tool identity, signed manifests, TOFU pinning, capability descriptors, a two-gate invocation policy, signed+chained receipts, publisher key rotation, and per-agent OAuth 2.1 auth scope","downloads_weekly":0,"deprecated":false,"health":{"score":61},"_cache":"db_only_bot","_partial":true,"_response_ms":1,"_powered_by":"depscope.dev — bot fast path (DB-only)","recommendation":{"action":"review"}}