MCP Server Check

Check an MCP server before you install it

Paste the server's tool list and the command you'd install it with. You'll see hidden instructions in tool descriptions, tools that try to steer other tools, code execution, file writes and unpinned installs, with a fix for each.

Nothing leaves your browser, and the server is never contacted. The page is blocked from making network requests.

What it checks

Checking your client's config file instead? Use the MCP config security checker.

Questions

Does this connect to the MCP server?

No. You paste what the server declares (the JSON its tools/list method returns) and the check runs in this page. The page blocks all outgoing requests, so nothing you paste is sent anywhere.

How do I get a server's tool list?

Most MCP clients can show the tools a server offers, and the MCP Inspector displays the tools/list response. Many servers also document their tools in the README; paste them as a JSON array of {name, description, inputSchema}.

What's the difference from mcpsecuritykit.com?

MCP Security Kit checks your client configuration file (secrets, pinning, file access, containers). MCP Server Check reviews one server's tools before you add it: hidden instructions, instructions about other tools, code execution and annotations that don't match.

Is a clean result a guarantee?

No. It checks what the server declares today with pattern rules. A server can behave differently from its descriptions, and a later version can change them. Pin the version you reviewed.

Sources