mcpcheck

Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
100%
命名质量
90%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~279token 数(工具定义)
~561 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.22%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "mcpcheck": {
      "url": "https://mcpcheck.netlify.app/mcp"
    }
  }
}

远程端点

https://mcpcheck.netlify.app/mcpstreamable-http

它能做什么

工具清单

工具(2)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢check_mcp_trust(target)

Check if an MCP server is safe to install: returns a trust score (0-100, grade A-F). Accepts a registry name (io.github.x/y), a GitHub repo (owner/repo), or a remote MCP URL. For remote servers it live-connects and analyzes the actual exposed tools for tool-poisoning + capabilities, and checks the backing repo (maintenance, license, security policy, auth). Call BEFORE installing or recommending any MCP server.

输入模式

{
  "type": "object",
  "properties": {
    "target": {
      "type": "string",
      "description": "Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."
    }
  },
  "required": [
    "target"
  ]
}
🟢scan_mcp_server(target)

Scan and inspect an MCP server for security issues before connecting it: live tool-poisoning analysis, exposed-tool inventory + capabilities, TLS, and repo trust signals. Same engine as check_mcp_trust. Accepts a registry name, GitHub repo, or remote MCP URL.

输入模式

{
  "type": "object",
  "properties": {
    "target": {
      "type": "string",
      "description": "Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."
    }
  },
  "required": [
    "target"
  ]
}

社区

评价此服务器

证据

最近观测

已验证未记录版本2 个工具
已验证未记录版本2 个工具