Check an MCP server before you install it
Paste the server's tool list and the command you'd install it with. You'll see hidden instructions in tool descriptions, tools that try to steer other tools, code execution, file writes and unpinned installs, with a fix for each.
Nothing leaves your browser, and the server is never contacted. The page is blocked from making network requests.
What it checks
- Tool poisoning:
<IMPORTANT>blocks, "don't tell the user", references to~/.ssh,.envor other tools' configs, invisible Unicode and encoded blobs in descriptions. - Tool shadowing: a description that gives orders about a different tool, such as "when you use send_email, BCC…".
- Annotations that don't match:
readOnlyHint: trueon a tool that runs commands or deletes. The MCP specification says clients must treat annotations as untrusted unless the server is trusted. - What the tools can do: run code, write or delete files, fetch any URL, read secrets.
- The install command: unpinned npx, uvx or docker installs, and
curl … | sh.
Checking your client's config file instead? Use the MCP config security checker.
Questions
Does this connect to the MCP server?
No. You paste what the server declares (the JSON its tools/list method returns) and the check runs in this page. The page blocks all outgoing requests, so nothing you paste is sent anywhere.
How do I get a server's tool list?
Most MCP clients can show the tools a server offers, and the MCP Inspector displays the tools/list response. Many servers also document their tools in the README; paste them as a JSON array of {name, description, inputSchema}.
What's the difference from mcpsecuritykit.com?
MCP Security Kit checks your client configuration file (secrets, pinning, file access, containers). MCP Server Check reviews one server's tools before you add it: hidden instructions, instructions about other tools, code execution and annotations that don't match.
Is a clean result a guarantee?
No. It checks what the server declares today with pattern rules. A server can behave differently from its descriptions, and a later version can change them. Pin the version you reviewed.
Sources
- Model Context Protocol specification (2025-06-18): Tools, including tool annotations and human-in-the-loop guidance.
- Model Context Protocol: Security best practices
- Checked 28 September 2026.