An observation record, not an assessment. Every row below is a change we recorded directly, with the content hash before and after. https://mcp.trustydata.app/mcp
| observed at (UTC) | change | version signal | reported version | tools | surface hash |
|---|---|---|---|---|---|
| 2026-10-10 19:40:03Z | DESCRIPTION_CHANGED | version-signalled | 4.0.11 → 4.1.0 | no tool-name change recorded | 0aa0983ca9c8 → 927eb064984a |
This section is identical for ~92% of publishers and is published as
shared context, not as a finding about mcp.trustydata.app. 90 dependency
packages sit beneath the measured MCP population; 41 have a
single maintainer and 31 have not published in over two years.
The widest is zod at
80.46% of npm-backed servers (8529 servers,
1 maintainer, last publish 2026-09-13).
These are properties of the shared SDK dependency closure. Any page claiming this set as
one operator's personal exposure is misreading a universal fact as a private one.
Source: state/mcp-census/chokepoint-maintainers.json, as_of 2026-10-07.
Observation window 2026-09-21 → 2026-10-10.
22,294 servers were observed; 2,214
were seen to change and 20,080 were observed and
recorded no change — that negative control is why a non-zero count here means something.
Across the corpus, 4,781 of
6,334 changes carried no version signal, and
1,690 of those added or removed tools.
What this does NOT cover: servers outside the observed set; changes that
occurred before 2026-09-21; changes that began and reverted between two observations;
and any server reachable only with credentials we do not hold. A server's absence from this
record is not evidence it did not change — only that we did not observe it.
Universe captured 2026-10-10T19:40:03.823Z. Produced by core/surface_history_page.cjs (reads core/surface_clock producers).
Hashes are of the served tool surface and are recomputable from the server's own response.