mcpcheck
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"mcpcheck": {
"url": "https://mcpcheck.netlify.app/mcp"
}
}
}远程端点
https://mcpcheck.netlify.app/mcpstreamable-http它能做什么
工具清单
工具(2)
🟢check_mcp_trust(target)
Check if an MCP server is safe to install: returns a trust score (0-100, grade A-F). Accepts a registry name (io.github.x/y), a GitHub repo (owner/repo), or a remote MCP URL. For remote servers it live-connects and analyzes the actual exposed tools for tool-poisoning + capabilities, and checks the backing repo (maintenance, license, security policy, auth). Call BEFORE installing or recommending any MCP server.
输入模式
{
"type": "object",
"properties": {
"target": {
"type": "string",
"description": "Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."
}
},
"required": [
"target"
]
}🟢scan_mcp_server(target)
Scan and inspect an MCP server for security issues before connecting it: live tool-poisoning analysis, exposed-tool inventory + capabilities, TLS, and repo trust signals. Same engine as check_mcp_trust. Accepts a registry name, GitHub repo, or remote MCP URL.
输入模式
{
"type": "object",
"properties": {
"target": {
"type": "string",
"description": "Registry name (io.github.x/y), GitHub repo (owner/repo), or remote MCP URL (https://...)."
}
},
"required": [
"target"
]
}社区
证据