mcpcheck

Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
90%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~279Tokens (tool definitions)
~561 BTypical response size
Minimal attention impact (0.22% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "mcpcheck": {
      "url": "https://mcpcheck.netlify.app/mcp"
    }
  }
}

Remote endpoints

https://mcpcheck.netlify.app/mcpstreamable-http

What it can do

Tool inventory

Tools (2)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢check_mcp_trust(target)

Check if an MCP server is safe to install: returns a trust score (0-100, grade A-F). Accepts a registry name (io.github.x/y), a GitHub repo (owner/repo), or a remote MCP URL. For remote servers it live-connects and analyzes the actual exposed tools for tool-poisoning + capabilities, and checks the backing repo (maintenance, license, security policy, auth). Call BEFORE installing or recommending any MCP server.

Input Schema

{
  "type": "object",
  "properties": {
    "target": {
      "type": "string",
      "description": "Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."
    }
  },
  "required": [
    "target"
  ]
}
🟢scan_mcp_server(target)

Scan and inspect an MCP server for security issues before connecting it: live tool-poisoning analysis, exposed-tool inventory + capabilities, TLS, and repo trust signals. Same engine as check_mcp_trust. Accepts a registry name, GitHub repo, or remote MCP URL.

Input Schema

{
  "type": "object",
  "properties": {
    "target": {
      "type": "string",
      "description": "Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."
    }
  },
  "required": [
    "target"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded2 tools
verifiedversion not recorded2 tools