We’re testing the MCP ecosystem for receipt-required dangerous actions.
We scanned the full public MCP registry: 43,801 servers, and 10% advertise a capability that can move money, destroy or export data, deploy infrastructure, or change permissions. Almost none require a verifiable human authorization before that action runs. RR-1 is how a maintainer fixes that — and gets credit for it.
RR-1 is a maintainer credential, not a warning. A server at RR-1 makes its most dangerous action safer than the ecosystem default — where 10% of registered MCP servers advertise a high-risk capability and almost none require a verifiable human authorization before it runs.
What RR-1 does.
RR-1 means one thing: your documented dangerous tool structurally declares a required receipt input, and a reference implementation proves it refuses calls without one.
RR-1 is not.
RR-1 is not a vulnerability report, a conformance badge for a full protocol, a claim about runtime enforcement, or a legal compliance statement. It is simply: we tested this tool's documented interface and it structurally requires a receipt.
How to earn RR-1.
Wrap your dangerous tool call with the Receipt Required middleware, point the test harness at your schema, and confirm the result. The whole integration takes about 10 minutes.
Once you pass the harness, link to rr-1.json in your repo root (template at @emilia-protocol/require-receipt/rr-1.json.example) and add the badge to your README.
The RR-1 registry starts here.
No maintainers are listed yet. The first public entry will appear only after its declared tool surface passes the RR-1 harness and publishes the result.