TheBotique

Methodology

What we collect, how, and what we deliberately do not claim. Version 1, 2026-09-03.

What we do

Once a day we read the public APIs of five registries — the official MCP Registry, ClawHub, Smithery and the npm registry (both search and per-package documents) — and record a normalized copy of each extension’s published record. We compute a SHA-256 hash over that normalized record. When the hash differs from the previous observation, we store a new observation. Identical re-reads are not stored.

What we record

What we exclude, and why

Counters that move constantly — download totals, install counts, usage figures — are recorded but deliberately excluded from the hash. Including them would make every daily read look like a change and render the entire record meaningless. Verified: an immediate second collection run across all sources produced zero changes.

What we do not claim

We do not label extensions as abandoned, dead, malicious, safe or verified, and we publish no composite score. Those are conclusions; we publish the timestamped observation that a reader can use to reach their own. “No issues detected” would mean nothing here, so we never say it: absence of a recorded change is not evidence of safety. We do not execute, sandbox or behaviourally analyse any extension.

Known limitations