Skip to content

[External Plugin]: eczid-mcp-trust #2920

Description

@Ecocitizenz

Plugin name

eczid-mcp-trust

Short description

Free agent plugin, MIT-licensed: no purchase, account, sign-in, licence key or trial is required, and nothing it does is withheld pending a purchase. See what the MCP servers configured in a workspace can reach: declared servers, launch commands, credential-shaped environment key names (never values) and any ECZ-ID public proof reference, with a deterministic Review Priority and what to review next. Inspection only. Free.

GitHub repository

Ecocitizenz/eczid-agent-plugins

Plugin path inside the repository

plugins/eczid-mcp-trust

Ref to review

No response

Commit SHA to review

ea0f04a4aa3d9f7b77753cd5d9380d34cbc2d374

Version

0.1.1

License identifier

MIT

Author name

EcoCitizenz Ltd

Author URL

https://developers.ecocitizenz.com

Homepage URL

https://developers.ecocitizenz.com/mcp-trust/

Keywords

ecz-id
mcp
mcp-server
mcp-config
model-context-protocol
security
review
credential-shaped

Additional notes for reviewers

PRICING, STATED PLAINLY: this plugin is free and MIT-licensed. It installs and runs in full with no account, sign-in, licence key, trial or paywall, and it sells nothing.

EcoCitizenz separately sells Pro editions of its VS Code extensions and ECZ-ID Passports through TrustOps. Those are different products. This plugin does not sell, unlock, gate or require any of them, and it never runs checkout or grants entitlement. Where a paid route is genuinely the next step for a result, the plugin links to it, clearly labelled optional, below the free capability it has already given.

The README has been corrected at the generator so this cannot be misread: it opens with "Free agent plugin. No purchase required.", every price sits below the doctrine and privacy sections under an explicit "Optional and separate ... a different product" heading, and suggested next actions are split into free routes and clearly-labelled optional paid ones. Tests fail the build if a price appears above the free statement.

Agent Plugins 1.0.0 package. The skill runs a dependency-free Node script that lists file names and paths only (explicit opt-in for .vscode, .mcp, .cursor and similar config directories), opens no file, makes no network call and writes nothing; it reports EVIDENCE OBSERVED / NOT OBSERVED, a Review Priority (LOW / NORMAL / ELEVATED / HIGH) with reasons, and at most three next actions. Also configures the read-only ECZ-ID Verifier MCP server (@ecocitizenz/ecz-id-mcp-verifier@0.9.0). Same detectors and doctrine as the free ECZ-ID MCP Trust VS Code extension. OBSERVED is never presented as ENFORCED.

Submission checklist

  • The plugin lives in a public GitHub repository.
  • The ref and/or sha I provided is immutable (release tag and/or full 40-character commit SHA), not a branch.
  • This submission follows this repository's contribution, security, and responsible AI policies.
  • This plugin is not already listed in the Awesome Copilot marketplace.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    external-pluginPublic external plugin submissionneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskready-for-reviewSubmission passed intake validation and is ready for maintainer review

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions